Security and data

What we hold. What we never touch.

How ChargeSecured handles money, card data, verification data, and evidence records, in plain terms. The privacy policy and user agreement control; this page summarizes them.

Read the privacy policyNotices and disclosures
Money

Never in the flow of funds.

Payments settle through licensed processors directly to you. ChargeSecured never holds, custodies, or escrows funds, and receives only its disclosed fees.

Card data

Handled to PCI DSS requirements.

We do not store full, unencrypted card numbers except as strictly necessary to operate the service, within applicable PCI DSS scope.

Verification data

Sensitive, by policy.

Signature, government ID information, and facial-match data captured at step-up are treated as sensitive: notice and consent where required, a defined retention and destruction schedule, never sold.

Evidence records

Kept as long as the dispute rules need them.

Transaction, evidence, and dispute records are retained to provide the service, meet card-network retention requirements, resolve disputes, and comply with law, then deleted or de-identified.

Two paths from the register

Card data goes to your processor. The record comes to us.

Register or checkoutCard data · authorization and settlement · never ChargeSecuredYour processorCard networkIssuerEvidence · linked to the transaction as it happensChargeSecured evidence recordIssuer, through your acquireronly when a dispute is filedThe merchant portal reads the record. Card numbers are not part of it.

What we collect, when, and why.

Summarized from the privacy policy. Where this table and the policy differ, the policy controls.

DataCapturedUsed forShared withKept
Merchant account data: business name, entity type, address, tax identifiers, banking details for payouts, authorized usersAt onboardingAdministering accounts, payouts and fees, fraud detection, securityPayment processors and acquiring banks; service providers for hosting and supportFor the life of the account, then per the retention schedule
Transaction data: items, amounts, timestamps, terminal or checkout context, source systemOn every protected saleThe evidence record; accounting, disputes, payouts, and reporting in the portalCard networks and issuers in authorization, verification, and dispute processes; processorsAs long as needed for the service, network retention, disputes, and law
Step-up verification data: signature, government ID information, facial-match dataOnly when a transaction's score triggers a step-up, under posted noticeVerifying the person completing the transaction; the transaction's evidence recordIssuers and networks in a dispute; terminal software providers as needed to operateA defined retention and destruction schedule. Never sold
Card dataAt paymentAuthorization and settlement by your processorProcessors, acquiring banks, networks, issuersNot stored unencrypted except as strictly necessary within PCI DSS scope
API keys and portal credentialsCreated in the portalAccess controlNobodyKeys stored as a hash only; revocable instantly

Sources: privacy policy sections on information we collect, how we share it, card data, sensitive verification data, retention, and your rights. Service providers who support hosting, analytics, and customer support may process data on our behalf under contract.

How access works.

The engineering facts behind the policy, as documented for developers.

State law, in the open.

Biometric privacy

Notice, consent, destruction schedule.

Where step-up verification captures a signature, government ID, or facial-match image, state biometric laws may apply: Illinois BIPA, Texas CUBI, Washington RCW 19.375. We provide the required notice, obtain any required consent, and apply a defined retention and destruction schedule.

Biometric notice →
Consumer privacy rights

Access, correct, delete, opt out.

Depending on where you live, you may have rights under the California CCPA and CPRA and the Virginia, Connecticut, and Utah privacy acts, including the right to know, correct, and delete personal information and to opt out of sale or sharing.

Privacy policy →
What we don't claim

Only what the policy commits to.

We do not list certifications we do not hold, and we do not describe capabilities beyond what is disclosed here and in the policy. Ask at assessment for what applies to your deployment, and it goes into your file.

Ask a question →

Questions from your counsel or your processor? Send them over.

Contact usPrivacy policy

Charge Secured LLC is not a bank, payment processor, insurer, or law firm. This page is a summary and not legal advice; the privacy policy, user agreement, and notices control.