How ChargeSecured handles money, card data, verification data, and evidence records, in plain terms. The privacy policy and user agreement control; this page summarizes them.
Payments settle through licensed processors directly to you. ChargeSecured never holds, custodies, or escrows funds, and receives only its disclosed fees.
We do not store full, unencrypted card numbers except as strictly necessary to operate the service, within applicable PCI DSS scope.
Signature, government ID information, and facial-match data captured at step-up are treated as sensitive: notice and consent where required, a defined retention and destruction schedule, never sold.
Transaction, evidence, and dispute records are retained to provide the service, meet card-network retention requirements, resolve disputes, and comply with law, then deleted or de-identified.
Summarized from the privacy policy. Where this table and the policy differ, the policy controls.
| Data | Captured | Used for | Shared with | Kept |
|---|---|---|---|---|
| Merchant account data: business name, entity type, address, tax identifiers, banking details for payouts, authorized users | At onboarding | Administering accounts, payouts and fees, fraud detection, security | Payment processors and acquiring banks; service providers for hosting and support | For the life of the account, then per the retention schedule |
| Transaction data: items, amounts, timestamps, terminal or checkout context, source system | On every protected sale | The evidence record; accounting, disputes, payouts, and reporting in the portal | Card networks and issuers in authorization, verification, and dispute processes; processors | As long as needed for the service, network retention, disputes, and law |
| Step-up verification data: signature, government ID information, facial-match data | Only when a transaction's score triggers a step-up, under posted notice | Verifying the person completing the transaction; the transaction's evidence record | Issuers and networks in a dispute; terminal software providers as needed to operate | A defined retention and destruction schedule. Never sold |
| Card data | At payment | Authorization and settlement by your processor | Processors, acquiring banks, networks, issuers | Not stored unencrypted except as strictly necessary within PCI DSS scope |
| API keys and portal credentials | Created in the portal | Access control | Nobody | Keys stored as a hash only; revocable instantly |
Sources: privacy policy sections on information we collect, how we share it, card data, sensitive verification data, retention, and your rights. Service providers who support hosting, analytics, and customer support may process data on our behalf under contract.
The engineering facts behind the policy, as documented for developers.
sales:write, disputes:write, read. A key can never read or write another merchant's data.cs_test_ keys before going live.external_id on every write makes retries safe. The same id always returns the original record instead of creating a second one.Where step-up verification captures a signature, government ID, or facial-match image, state biometric laws may apply: Illinois BIPA, Texas CUBI, Washington RCW 19.375. We provide the required notice, obtain any required consent, and apply a defined retention and destruction schedule.
Biometric notice →Depending on where you live, you may have rights under the California CCPA and CPRA and the Virginia, Connecticut, and Utah privacy acts, including the right to know, correct, and delete personal information and to opt out of sale or sharing.
Privacy policy →We do not list certifications we do not hold, and we do not describe capabilities beyond what is disclosed here and in the policy. Ask at assessment for what applies to your deployment, and it goes into your file.
Ask a question →Charge Secured LLC is not a bank, payment processor, insurer, or law firm. This page is a summary and not legal advice; the privacy policy, user agreement, and notices control.