Last updated: [DATE] · Effective: [EFFECTIVE_DATE]
PayClaw LLC (“PayClaw,” “we,” “us,” “our”) provides a technology platform that enables AI agents to make authorized purchases on behalf of users using virtual payment cards. Virtual cards are issued by [BANK_NAME], Member FDIC, through our card issuing partner Lithic, Inc. PayClaw is a technology partner and program manager — not a bank, card issuer, or money transmitter.
This Privacy Policy explains how we collect, use, and protect your information when you use our website, dashboard, API, and MCP server (collectively, the “Service”). We collect only the information necessary to provide the Service.
When you create an account, we collect your email address and authentication credentials. If you sign in via GitHub or Google, we receive your name and email from those providers. For KYC verification, our card issuing partner Lithic, Inc. collects your name, address, date of birth, and government-issued identification as required by applicable law.
We record purchase intents (merchant, estimated amount, description), transaction outcomes (actual amount, merchant name), and auto-audit results. This data powers your dashboard, our intent authorization engine, and our compliance obligations.
We store a one-way cryptographic hash of your API keys. We cannot see or recover your raw API key after creation.
We collect standard server logs (IP address, request timestamps, user agent) for security monitoring, rate limiting, and abuse prevention.
We process your information on the following bases:
We share data with the following partners, solely to operate the Service. Each partner operates under a data processing agreement with PayClaw.
Lithic, Inc. & [BANK_NAME], Member FDIC
Our card issuing partner and sponsor bank. Receives your name, address, date of birth, and government ID for KYC verification and card issuance. Processes virtual card transactions. Subject to Lithic's Privacy Policy.
Stripe
Processes account deposits. Receives your payment card details directly. PayClaw does not see or store your payment card number. Subject to Stripe's Privacy Policy.
Supabase
Hosts our database and authentication system. Stores your account data, transaction records, and hashed API keys. Data stored in the United States. Subject to Supabase's Privacy Policy.
Vercel
Hosts our web application. May collect anonymous performance metrics. Subject to Vercel's Privacy Policy.
Resend
Sends transactional emails (account verification, transaction notifications, security alerts). Receives your email address and notification content.
When your agent completes a purchase, virtual card credentials are shared with the merchant to process the transaction. This is inherent to how card payments work and is not a “sale” of your data.
We do not sell your data to third parties. We do not share your data for cross-context behavioral advertising. We do not use your data for advertising.
We retain your account data and transaction history for as long as your account is active. Transaction records and audit logs are retained for a minimum of 7 years to comply with financial record-keeping requirements.
You may request account deletion by contacting us. Upon deletion, we will remove your account data except where retention is required by law (including financial record-keeping obligations, ongoing investigations, or fraud prevention). Non-financial account data (such as notification preferences) is deleted promptly upon account closure.
We use strictly necessary cookies to maintain your authenticated session. These cookies are required for the Service to function and cannot be disabled.
We do not use cookies for advertising or cross-site tracking. Our hosting provider (Vercel) may collect anonymous performance metrics. Our authentication provider (Supabase) uses session cookies for login state.
You can control cookies through your browser settings, but disabling session cookies will prevent you from using the Service.
PayClaw's intent authorization engine uses automated processing to evaluate purchase requests from your AI agents. This includes checking purchase intents against your configured spending limits, merchant whitelists, and per-intent caps. Transactions may be automatically approved or declined based on these rules.
Our post-purchase auto-audit system automatically flags transactions where the actual charge deviates from the declared intent by more than 20%.
You may request human review of any declined transaction or audit flag by contacting support@payclaw.io.
In the event of a security breach involving your personal information, we will notify you in accordance with applicable law. Notification will include: the nature of the breach, the types of information involved, the steps we are taking to address it, and steps you can take to protect yourself.
We maintain a written security incident response plan and will cooperate with applicable regulators as required.
Depending on your jurisdiction, you may have the right to:
To exercise these rights, contact us using the methods listed in Section 14. We will respond to verifiable requests within 45 days.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):
To exercise these rights, contact us at privacy@payclaw.io or write to us at the mailing address in Section 14. We will verify your identity before processing your request and respond within 45 days.
In the preceding 12 months, we have collected the following categories of personal information:
The Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child under 13, we will promptly delete that information.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@payclaw.io.
Your data is stored and processed in the United States. Our service providers (Supabase, Vercel, Stripe, Lithic) primarily process data in the United States. If any sub-processor processes data outside the US, they do so under appropriate data transfer safeguards.
We may update this Privacy Policy from time to time. We will notify you of material changes via email or a notice on our website at least 30 days before changes take effect. Your continued use of the Service after changes constitutes acceptance.
For privacy questions, data requests, or concerns:
For transaction disputes or unauthorized activity, contact support@payclaw.io.