Legal

Privacy

The short version: we collect as little as possible, we encrypt everything, and we never sell data. The longer version follows.

This website

finscale.dev, docs.finscale.dev, and api.docs.finscale.dev are static sites. They set no cookies, run no analytics or advertising scripts, and load nothing from third-party hosts. Standard web-server logs (IP address, user agent, requested URL) are retained briefly by our hosting infrastructure for security and capacity monitoring, then discarded.

The sandbox

The test environment exists so you can evaluate the API with simulated data. Do not send real cardholder data, real personal data, or production secrets to the sandbox — test values are documented in Testing. Sandbox requests may be logged for debugging and abuse prevention and are periodically purged.

The payment platform

When merchants process live payments through Finscale, we handle payment data as a processor on the merchant's behalf, under the agreement that governs their account. The operating principles:

  • Minimal collection. We process the data a transaction needs — nothing more.
  • Encryption everywhere. TLS in transit, encryption at rest, and tokenization so card data never touches merchant servers. See Security.
  • No resale. Payment data is never sold, rented, or used for advertising.
  • EU residency. Platform data is stored and processed in the European Union.
  • Subprocessors under contract. Payment providers in the routing set receive only what they need to authorize and settle a transaction, and are bound by data-processing agreements.
  • Your rights. Access, correction, deletion, and portability requests are honored per applicable data-protection law, including the GDPR.

Contact

Privacy questions, data-subject requests, and security reports are handled through your Finscale account representative.

Changes

If this policy changes materially, the current version is always the one published at this URL.