Legal
Paybond Privacy Policy
1. Scope and roles
This Privacy Policy applies to Paybond public websites, self-serve signup, hosted console, APIs, SDKs, product workflows, support, billing, and related services. "Paybond" means the Paybond entity identified in your order form, invoice, or other contracting record.
Paybond is generally the controller for account, website, billing, support, and service operations data. For tenant-submitted workflows, evidence, operator records, identity-provider settings, settlement configuration, and other customer content, Paybond processes that data to provide the service under the customer's instructions and applicable agreement.
Tenant isolation
Paybond designs its service so tenant scope is derived from authenticated credentials. Client-sent tenant identifiers are not the source of truth for authorization.
2. Data we collect
| Category | Examples |
|---|---|
| Account and organization data | Name, work email, organization name, workspace realm, plan, role, signup status, and account settings. |
| Authentication and operator data | Login identifiers, session metadata, role and permission assignments, API key metadata, SSO or SCIM configuration, trusted agent keys, support-session audit fields, and console activity needed to run tenant-scoped access controls. |
| Tenant configuration and product data | Business configuration, settlement rail choices, linked Stripe destination status, x402 Base receive address configuration, identity-provider settings, policy versions, dispute records, evidence references, signed mandate imports, receipts, ledger provenance, audit exports, and related workflow records. |
| Bank account linking and ACH verification data | When a bank account is linked to fund the Stripe ACH settlement rail: an encrypted Plaid access token for the linked account, bank display metadata (institution name, account mask or last four, and verification status), Stripe customer and bank-account or payment-method identifiers, and redacted risk-check outcomes such as an Identity Match name-match score, a balance-sufficiency result, or a Signal risk tier. Paybond does not store the Plaid public token or full bank account and routing numbers on the standard path. |
| Billing and commercial data | Plan selection, subscription status, Stripe customer, subscription, invoice, checkout, portal, and billing identifiers, usage records, and billing communications. |
| Support and communications | Messages, troubleshooting context, attachments you provide, contact-sales requests, operational notices, and incident follow-up. |
| Website and analytics data | Public page path, referrer, landing page, UTM fields, ad click identifiers such as gclid or fbclid when present in the URL, call-to-action label and destination, viewport and screen dimensions, language, timezone, cookie and browser context, visitor ID, session ID, user agent, source IP, approximate country or routing metadata from security providers, and bot/device classification. Signup funnel conversion events may include plan selection and a one-way SHA-256 hash of the billing owner email domain (not the full email address). |
| Feedback you submit through the on-site widget | The free-text answer you type, the randomly-selected question you were shown, an email address only if you choose to provide one, the page path and URL where you submitted feedback (public pages or the authenticated console), and basic technical context (browser user agent, viewport size, language, timezone, and submission time). See Section 7 for how this is used and handled. |
| Security, logs, and telemetry | Request IDs, tenant identifiers, timestamps, authentication and session events, rate-limit signals, webhook delivery status, structured service logs, traces, and incident records. |
3. Sources of data
- You and your authorized operators when you create accounts, configure workspaces, submit product data, or contact Paybond.
- Your organization, identity provider, SCIM provisioner, trusted agent keys, SDK or API clients, and other tenant-directed systems.
- Payment, settlement, and billing providers such as Stripe and Coinbase CDP Payments, and settlement rail providers you connect directly to your workspace with your own merchant credentials — for example Shopify, Adyen, Flutterwave, or Paystack — when those rails are enabled.
- Plaid, when a bank account is linked for the Stripe ACH settlement rail, for account verification and, where amount and risk policy require it, Identity Match, Balance, and Signal risk evaluations.
- Public website, console, API, browser, network, and infrastructure logs generated when you use Paybond.
4. How we use data
- Provide, secure, maintain, and improve Paybond services, including signup, billing, authentication, SSO, SCIM, policy workflows, disputes, settlement lifecycle operations, Signal records, audit exports, and support.
- Enforce tenant isolation, authenticate operators, prevent cross-tenant access, detect abuse, investigate security incidents, and preserve auditability.
- Process subscriptions, invoices, plan changes, usage records, tax and accounting records, and contract-managed exceptions.
- Operate public analytics for product, marketing, reliability, and conversion measurement without exposing one tenant's workflows to another tenant.
- Comply with law, enforce agreements, respond to lawful requests, and protect the rights, safety, and security of Paybond, customers, operators, and third parties.
Where law requires a specific legal basis, Paybond relies on contract performance, legitimate interests in operating and securing the service, compliance with legal obligations, consent where required, and the customer's instructions for customer-controlled product data.
5. Bank account linking and ACH verification (Plaid)
Some workspaces fund ACH settlement by linking a bank account. When you or your authorized operator link a bank account for the Stripe ACH settlement rail, Paybond uses Plaid to verify the account. Plaid does not move money; Stripe remains the money mover and merchant of record for ACH debits.
Account verification uses Plaid Auth to confirm the linked account. For higher-value, agent-funded ACH debits, a server-managed amount and risk policy may additionally require Plaid Identity Match, Balance, and/or Signal evaluations before the debit is authorized; Auth alone is not sufficient above the configured thresholds. These checks support account validation and fraud monitoring for agent-funded settlement, including in a NACHA WEB debit context. Paybond does not present them as legal advice or as a compliance determination for your organization.
| Data | How Paybond handles it |
|---|---|
| Plaid Link public token | The short-lived token created while linking is exchanged server-side and is not stored or logged. |
| Bank access token | The Plaid access token used to query the linked account server-side is encrypted at rest and is never returned to browsers, SDKs, or agents. |
| Account and routing numbers | On the standard path Paybond uses a one-time Stripe processor token to attach the account and does not store full account or routing numbers. |
| Bank display metadata | Institution name, account mask or last four, and verification status are stored so operators can see the linked account. |
| Risk decision outcomes | Identity Match, Balance, and Signal results are stored as redacted, tenant-scoped decisions — for example a name-match score, a balance-sufficiency result, or a Signal risk tier — not raw identity fields, full balances, or account numbers. |
Operator and compliance control
Linking a bank account through Plaid and authorizing an ACH debit are separate steps; Stripe collects the applicable ACH (Nacha) mandate when the payment is confirmed. Whether the additional Plaid risk checks are required in production, and at what thresholds, is controlled by operator configuration and gated by Paybond's internal compliance sign-off before those thresholds are enabled for live debits.
7. On-site feedback widget
Public pages (marketing, docs, and guides) and the authenticated operator console — but not the internal staff console, the first-run onboarding checklist, or sign-in/sign-up flows — may show a small, dismissible feedback prompt asking a short, randomly-selected question, such as what you would change about the page. The exact question varies by visit rather than by page. Submitting it is entirely optional, and dismissing or ignoring it never blocks or limits your use of the site or console. Once you have seen the prompt on a given page, it will not ask again on that same page; a separate cooldown also limits how often it can appear elsewhere.
If you submit feedback, Paybond collects the text you write, the question you were shown, the page path and URL, and basic technical context (browser user agent, viewport size, language, timezone, and submission time) to help us understand and reproduce what you reported. The email field is optional and used only to reply to you if you ask a question or report a problem that needs follow-up; it is never used for marketing you have not otherwise opted into. Feedback submitted from the authenticated console is not otherwise linked to your operator account or tenant beyond whatever you choose to write.
Feedback submissions are delivered directly to a Paybond product inbox for review and are not displayed publicly, attached to your account, or used to build an advertising profile. Paybond retains feedback messages only as long as needed to review, act on product-improvement input, and respond if you provided an email and asked a question, then deletes or de-identifies them.
9. Retention
Paybond retains personal data for as long as needed to provide the service, satisfy legal and accounting obligations, preserve ledger and audit integrity, resolve disputes, investigate incidents, enforce agreements, and maintain security. Retention periods vary by data type and customer agreement.
| Data type | General retention approach |
|---|---|
| Account and billing records | Retained while the account or commercial relationship is active and as needed for tax, accounting, contract, and dispute obligations. |
| Ledger, receipts, audit exports, disputes, and settlement records | Retained as needed to preserve replayable product history, auditability, payment and dispute records, and customer obligations. |
| Linked bank account and ACH risk decisions | Encrypted Plaid access tokens, bank display metadata, and redacted risk-check outcomes are retained while the linked account is active and as needed for settlement, dispute, and audit obligations. When a link becomes inactive, the stored access-token ciphertext is purged. |
| Session and authentication records | Retained for operational security, account recovery, incident investigation, and abuse prevention. |
| Public analytics visitor cookie | The first-party visitor cookie is configured for up to one year unless deleted earlier by the browser or user. |
| Feedback widget submissions | Retained only as long as needed to review product-improvement input and, if you provided an email and asked a question, to respond — then deleted or de-identified. |
| Support communications | Retained while needed to answer the request, maintain account history, improve support quality, and satisfy legal obligations. |
10. Security
Paybond uses technical and organizational safeguards designed for a multi-tenant service: TLS encryption for data in transit, authenticated tenant scope, role-based access, httpOnly console session cookies, short-lived tokens, refresh rotation, encrypted storage for vaulted settlement destination credentials and linked bank-account access tokens, signed audit bundles, structured logging, provider-managed secret storage, and operational controls for elevated support access.
No service can guarantee absolute security. Customers are responsible for safeguarding their own operator credentials, tenant configuration, IdP settings, API keys, trusted agent keys, settlement destinations, and systems that call Paybond APIs.
11. International transfers
Paybond may process and store data in the United States and other locations where Paybond, its affiliates, or subprocessors operate. If applicable law requires transfer safeguards, Paybond uses appropriate contractual and operational measures in customer agreements or data processing terms.
12. Your rights and choices
Depending on where you live and how you use Paybond, you may have rights to request access, correction, deletion, portability, restriction, objection, or appeal of a privacy decision. Authorized agents may submit requests where law permits. Paybond will verify requests before acting on them.
If you are located in the European Economic Area, United Kingdom, Switzerland, or a U.S. state with a comprehensive consumer privacy law, that law may define these rights — and any related opt-out rights — more specifically than this general summary. Paybond intends to honor verifiable requests under the law that applies to you; contact [email protected] and identify your location so Paybond can apply the correct process.
- Privacy requests: [email protected].
- Contract, DPA, or formal notice requests: [email protected].
- Public analytics choices: delete or block cookies and local/session storage in your browser, use browser privacy controls, or contact Paybond for assistance with analytics data tied to a visitor ID.
- Feedback widget choices: dismiss the prompt at any time, leave the email field blank, or contact [email protected] to request deletion of a feedback submission you provided an email address with.
- Workspace data requests: contact your organization admin first when Paybond processes the data on behalf of your organization.
13. Children
Paybond is a business service and is not directed to children. Do not use Paybond to knowingly submit personal data about children unless your organization has a lawful basis and the relevant customer agreement permits that use.
14. Changes and contact
Paybond may update this Privacy Policy as the service, subprocessors, analytics, or legal requirements change. Material changes will be reflected by updating the effective or last-updated date and, where appropriate, by providing additional notice through the service, contract record, or email.
Privacy questions should go to [email protected]. Legal notices should go to [email protected] or the notice address stated in your order form or invoice.