Privacy Policy

Effective Date: January 2026

Quick Summary

We know privacy policies are long. Here's what you need to know:

  • ✓ We collect: Transaction metadata, IP addresses, CLI logs
  • ✗ We DON'T collect: Bank details, SSNs, passwords, ID documents, payment purposes
  • 🔒 Security: TLS encryption, data redaction, audit logging
  • ⏳ Retention: 3-7 years for financial records, 30 days for operational/debug logs
  • 🤝 Stripe: Processes payments and handles KYC (not us)
  • 📧 Your Rights: Access, delete, or export your data anytime
  • 🚫 No Selling Data: We never sell your information

👉 Read the full policy below for details.


1. Introduction

Ra Pay AI, LLC ("Ra Pay," "we," "us," or "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our command-line interface tool, API, and related services (the "Service").

Legal Basis for Processing

We process your data based on:

  • Contract Performance: To provide Ra Pay services and execute payment transactions (GDPR Art. 6(1)(b))
  • Legal Obligation: To comply with tax, fraud prevention, and anti-money laundering requirements (GDPR Art. 6(1)(c))
  • Legitimate Interest: To maintain system security, prevent fraud, and improve our services (GDPR Art. 6(1)(f))
  • Consent: Where explicitly obtained for specific purposes (GDPR Art. 6(1)(a))

By using Ra Pay, you consent to the data practices described in this Privacy Policy. If you do not agree, you should not use Ra Pay. This Privacy Policy should be read in conjunction with our Terms of Service.

Scope: This policy applies to all users of Ra Pay, including individuals, businesses, and AI agents operating on behalf of users.


2. Information Stored Locally

Ra Pay stores minimal configuration data locally on your device at ~/.rapay/config.toml

Data Stored Locally:

  • Your Stripe Connect account ID (public identifier)
  • API endpoint URL
  • Terms of Service version accepted
  • ToS acceptance timestamp

Data NOT Stored Locally:

  • Stripe secret API keys
  • Bank account numbers
  • Payment card numbers
  • Social Security numbers
  • Identity documents
  • Passwords or authentication tokens

File Permissions: On Unix systems (Linux, macOS), the config file is protected with 600 permissions (owner read/write only), preventing other users on the same system from accessing it.


3. Information We Collect Server-Side

When you use Ra Pay, we collect and store the following information on our servers:

Data TypeWhat We CollectPurposeLegal Basis
Transaction MetadataTransaction IDs, amounts, timestamps, sender/recipient account identifiers, statusProcess payments, calculate fees, resolve disputesContract, Legal obligation
Application Fee Records2% fee amount, calculation timestamp, payment statusTax compliance (IRS)Legal obligation
API Request LogsEndpoint accessed, HTTP method, response status, response timeMonitor performance, debug errors, detect abuseLegitimate interest
IP AddressesIPv4/IPv6 address from API requestsPrevent fraud, enforce rate limits, security investigationsLegitimate interest
User Agent StringsCLI version, operating system typeVersion-specific support, compatibilityLegitimate interest
ToS Acceptance RecordsVersion accepted, timestamp, IP addressDemonstrate legal agreement, resolve disputesContract, Consent
Account StatusActive/suspended/banned status, reason codesEnforce ToS, comply with Stripe requirementsContract, Legal obligation
Error LogsError codes, messages, stack traces (with sensitive data redacted)Diagnose issues, improve reliabilityLegitimate interest

How We Use This Data:

  • Process payment transactions and calculate application fees
  • Maintain system security and prevent fraud
  • Comply with tax reporting and legal obligations
  • Provide customer support and technical assistance
  • Improve Ra Pay's performance and reliability
  • Enforce our Terms of Service and detect abuse
  • Prepare for and defend against legal claims

4. Information We Do NOT Collect

Ra Pay does NOT collect, process, or store:

  • ✗ Bank account numbers or routing numbers
  • ✗ Payment card numbers (credit/debit)
  • ✗ Social Security numbers or tax identification numbers
  • ✗ Government-issued ID documents or images
  • ✗ Biometric data (fingerprints, facial recognition, etc.)
  • ✗ Browsing history or cookies (terminal-native = no browser)
  • ✗ Passwords or secret API keys
  • ✗ Stripe authentication tokens
  • ✗ Personal identifying information (PII) beyond what Stripe requires

5. Payment Purpose Data Handling (Privacy by Design)

Ra Pay requires a business purpose description for all payments. Here's how we handle this data with privacy as a priority:

Our Approach:

  • ✓ We require a business purpose description to be provided
  • ✓ We pass the purpose to Stripe for payment processing
  • ✗ We do NOT store payment purposes in our systems
  • 🔒 We only log purpose_provided: true/false

Why This Design:

  • Minimal data collection: We collect only what's necessary for compliance
  • Reduced liability: We cannot breach data we don't store
  • Your privacy: Your business details remain between you and Stripe
  • Compliance: Stripe maintains full records for regulatory purposes

What Stripe Stores:

Stripe stores the full payment purpose in the transfer.description field. This data is available in your Stripe Dashboard and subject to Stripe's Privacy Policy. For disputes, compliance inquiries, or data requests about payment purposes, contact Stripe directly.


6. How We Share Data with Stripe

Ra Pay Uses Stripe Connect as Our Payment Processor

When you use Ra Pay, we integrate with Stripe Connect to process payments. This creates a three-party relationship:

You↔Ra Pay↔Stripe

What Data We Share with Stripe:

  • Your Stripe Connect account ID (which you create directly with Stripe)
  • Transaction metadata: amounts, recipient account IDs, transfer instructions
  • Our 2% application fee amount (collected by Stripe on our behalf)

What Data Stripe Collects Directly from You (Not Through Us):

When you run ra link-bank, you are redirected to Stripe's hosted onboarding page where Stripe collects directly from you:

  • Legal name, date of birth, address
  • Government-issued ID (e.g., passport, driver's license)
  • Social Security Number or Employer Identification Number
  • Bank account details (account and routing numbers)
  • Business information (if applicable)

Important: Ra Pay does NOT have access to this sensitive KYC information. It is collected, processed, and stored exclusively by Stripe pursuant to Stripe's Privacy Policy and Stripe's Services Agreement.

How Stripe Uses Your Data:

  • Verify your identity (Know Your Customer / KYC compliance)
  • Screen for money laundering and fraud (Anti-Money Laundering / AML)
  • Process payments and hold funds in your Stripe balance
  • Comply with bank regulations and financial laws
  • File Suspicious Activity Reports (SARs) if required

Your Relationship with Stripe:

By using Ra Pay, you agree to create a direct contractual relationship with Stripe as a "Connected Account." You are bound by:

Ra Pay's Role: Ra Pay acts as a Stripe Connect Platform. We facilitate your access to Stripe's payment infrastructure, but we do not control Stripe's data practices. Questions about how Stripe uses your data should be directed to Stripe at [email protected] or via Stripe's Privacy Center.

Data Processing: For users subject to GDPR: Stripe acts as an independent data controller for KYC/AML data. Ra Pay and Stripe have entered into appropriate data processing terms under which Stripe processes transaction data on our behalf for payment processing purposes.

Data Controller Status: For data regarding your end-customers (the people paying you), You are the Data Controller and Ra Pay is a Data Processor. You are responsible for having your own privacy policy that informs your customers how their data is processed via Stripe and Ra Pay.


6. Third-Party Service Providers

In addition to Stripe, we may share limited data with the following service providers who assist in operating Ra Pay:

Service ProviderData SharedPurpose
Cloud Hosting (e.g., Railway, AWS)Transaction logs, API request logs, account metadataHost servers and databases
Error Monitoring (e.g., Sentry)Error logs (redacted), stack traces, CLI versionDetect and fix bugs

Data Processing Agreements:

All service providers are contractually required to:

  • Process data only on our instructions
  • Implement appropriate security measures
  • Not use data for their own purposes
  • Delete or return data upon request
  • Notify us of data breaches

International Transfers: Payment data is processed by Stripe in accordance with GDPR requirements. See Stripe's Privacy Policy for details.


7. Data Retention Policy

We retain data according to a tiered retention policy based on legal and business requirements:

Data CategoryRetention PeriodReason
Transaction Metadata5 yearsTax compliance (IRS), dispute resolution, Stripe expectations
Application Fee Records7 yearsIRS best practice for revenue documentation
ToS Acceptance Records5 yearsLegal defense, contract proof
Security/Access Logs1-3 yearsFraud prevention, PCI-DSS, investigation support
API Request Logs90 days - 1 yearPerformance monitoring, debugging
Operational/Debug LogsEngineering support only

After Expiration: Data is automatically deleted through scheduled cleanup processes. For sensitive data, records are securely deleted or overwritten to prevent recovery.

Legal Holds: If you are subject to a legal hold (due to litigation or investigation), we will retain all relevant data indefinitely until the hold is lifted.

User Deletion Requests: If you request deletion via email, we will delete eligible data subject to the retention periods above and any timeframes required by applicable law. Data required for tax compliance or ongoing legal proceedings will be retained per applicable law.


8. AI Agent and Automated Use

If you use Ra Pay through AI agents, bots, or automated systems:

You Are the Data Controller

You determine what personal data your AI agent processes through Ra Pay.

Ra Pay Is the Data Processor

Ra Pay processes data on your instructions via CLI commands.

Your Responsibilities

You are responsible for ensuring your AI agents comply with:

  • GDPR (if processing EU resident data)
  • CCPA (if processing California resident data)
  • All other applicable privacy and data protection laws

Unsolicited Sensitive Data: You agree not to include Protected Health Information (PHI), unredacted financial secrets, or other sensitive categories of data in CLI command arguments or API payloads. Ra Pay filters logs for common secrets but cannot guarantee redaction of unstructured text generated by AI agents.

Data Logging

Agent-generated metadata is included in transaction logs:

  • agent_id: Identifier of the AI agent
  • intent: Description of what the agent intended to do
  • reasoning: Why the agent initiated the transaction
  • timestamp: When the action occurred

This metadata is retained per our Data Retention Policy (Section 7).

Liability

See our Terms of Service Section 7 for detailed AI agent liability terms. You are fully liable for privacy violations by AI agents under your control.

Data Processing Agreement

Enterprise users deploying AI agents at scale may request a formal Data Processing Agreement (DPA) by contacting [email protected].


9. Data Security

We implement industry-standard security measures to protect your data from unauthorized access, disclosure, alteration, or destruction.

Technical Security Measures:

  • 🔒Encryption in Transit: All API communications use TLS 1.3 encryption (HTTPS)
  • 🔒Encryption at Rest: Database fields containing sensitive identifiers are encrypted using AES-256
  • 🔒Data Redaction: Passwords, API keys, tokens, and card numbers are automatically redacted from logs before storage
  • 🔒Access Controls: Admin access requires API key authentication, with credentials rotated periodically as part of our security review process
  • 🔒Secure Key Storage: Stripe API keys are never stored by Ra Pay; users store them locally with 600 file permissions
  • 🔒Audit Logging: All administrative actions and API requests are logged with timestamps
  • 🔒SQL Injection Prevention: Parameterized queries and ORM frameworks prevent SQL injection
  • 🔒Rate Limiting: API requests are rate-limited to prevent abuse

Organizational Security Measures:

  • 🔐Minimal Data Collection: We collect only data necessary to provide the Service
  • 🔐Least Privilege Access: Personnel access only data required for their role
  • 🔐Incident Response Plan: Documented procedures for responding to security incidents

Your Security Responsibilities:

While we implement strong security measures, no system is 100% secure. You are responsible for:

  • Protecting your local ~/.rapay/ directory and its contents
  • Not sharing your Stripe API keys with unauthorized parties
  • Using a strong password for your Stripe account
  • Enabling multi-factor authentication (MFA) on your Stripe account
  • Reporting suspected security incidents immediately to [email protected]
  • Keeping your CLI tool up-to-date with the latest version

10. Data Breach Notification

In the Event of a Data Breach:

If we discover a data breach that compromises your personal information, we will:

1. Investigation

Determine the scope, affected users, data types involved, and root cause.

2. Notification

Notify affected users via CLI notification upon next ra command execution and prominent notice on rapay.ai.

3. Remediation

Take immediate steps to contain the breach and prevent further unauthorized access.

What We Will Tell You:

  • Date and time of the breach
  • Types of data compromised (e.g., "transaction IDs and IP addresses")
  • Steps we've taken to mitigate harm
  • Contact information for questions

Regulatory Reporting:

We will report breaches to applicable regulators as required by law:

  • GDPR: Notification to supervisory authority within 72 hours (if affecting EU residents)
  • CCPA: Notification to California Attorney General if affecting >500 California residents
  • State Breach Laws: Compliance with breach notification laws in all 50 states

Your Right to Know: You may request details about any past breaches by contacting [email protected].


11. Your Privacy Rights

You have the following rights regarding your personal data:

RightWhat It MeansHow to Exercise
AccessRequest a copy of all data we hold about youEmail [email protected] with subject "Data Access Request"
CorrectionRequest correction of inaccurate or incomplete dataEmail [email protected] with corrected information
DeletionRequest deletion of your data (subject to retention requirements)Email [email protected] with subject "Data Deletion Request"
PortabilityRequest your data in machine-readable JSON formatEmail [email protected] with subject "Data Export Request"
ObjectionObject to processing based on legitimate interestEmail [email protected] explaining your objection
Local DeletionDelete all local configuration dataRun rm -rf ~/.rapay/ or delete folder manually

Identity Verification:

To protect your privacy, we will verify your identity before fulfilling requests. We may ask you to:

  • Confirm your Stripe Connect account ID
  • Provide the IP address from your last CLI session
  • Answer security questions about recent transactions

Limitations on Deletion:

We cannot delete data if:

  • Required for tax compliance (7 years for fee records)
  • Required for legal proceedings or disputes
  • Necessary to comply with legal obligations
  • Subject to ongoing fraud investigation

In these cases, we will restrict processing instead of deleting data.

California Residents (CCPA):

You have additional rights under the California Consumer Privacy Act:

  • Right to Know: What personal information we collect, use, disclose, and sell (we don't sell)
  • Right to Delete: Request deletion (subject to exceptions)
  • Right to Opt-Out: We do not sell personal information, so opt-out is not applicable
  • Right to Non-Discrimination: We will not discriminate against you for exercising CCPA rights

To exercise CCPA rights, email [email protected] with "CCPA Request" in the subject line.

EU Residents (GDPR):

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under GDPR:

  • Right to Access (Art. 15): Request a copy of your personal data
  • Right to Rectification (Art. 16): Request correction of inaccurate data
  • Right to Erasure (Art. 17): Request deletion ("right to be forgotten")
  • Right to Restrict Processing (Art. 18): Limit how we use your data
  • Right to Data Portability (Art. 20): Get your data in a portable format
  • Right to Object (Art. 21): Object to processing for legitimate interests
  • Right to Lodge a Complaint (Art. 77): File a complaint with your local Data Protection Authority

To exercise GDPR rights, email [email protected].

Authorized Agent Requests:

You may designate an authorized agent to make privacy requests on your behalf by providing written authorization to [email protected].


12. Law Enforcement and Legal Requests

We may disclose your information in response to valid legal process, including:

  • Court orders, subpoenas, or search warrants
  • Requests from law enforcement agencies (FBI, Secret Service, IRS, etc.)
  • Regulatory investigations (FinCEN, state banking regulators)
  • National security requests (if legally compelled)

Our Review Process:

  1. We review all requests for legal validity
  2. We narrow the scope to the minimum necessary data
  3. We object to overly broad or improper requests where legally appropriate
  4. We notify you unless legally prohibited (e.g., gag order)

What We May Disclose:

  • Stripe Connect account IDs
  • Transaction history (amounts, timestamps, sender/recipient IDs)
  • IP addresses and user agent strings
  • ToS acceptance records
  • Account status and suspension reasons
  • Account creation date and activity timeline

Emergency Requests:

We may disclose data without legal process in emergencies involving imminent harm (e.g., kidnapping, suicide prevention, terrorism). Such disclosures are logged and reviewed quarterly for appropriateness.


13. Automated Decision-Making and Profiling

Automated Decisions Affecting You:

Ra Pay uses automated systems to make certain decisions:

Decision TypeHow It WorksImpact on YouHow to Appeal
Fraud DetectionAlgorithm analyzes transaction patternsMay flag or temporarily hold suspicious transactionsEmail [email protected] with transaction ID
Rate LimitingAutomated enforcement of API request limitsMay temporarily block CLI access if limits exceededRequest limit increase review
Account SuspensionAutomated if Stripe terminates your Connected AccountImmediate loss of Ra Pay accessContact Stripe first; we reinstate if Stripe restores
ToS Violation DetectionAlgorithm flags prohibited activityMay result in account review or suspensionEmail [email protected] to appeal

Your Right to Human Review:

If an automated decision adversely affects you (e.g., account suspension, transaction hold), you may request human review by:

  1. Email [email protected] with subject "Appeal Automated Decision"
  2. Include transaction ID or account details
  3. Explain your position
  4. We will review your appeal and respond

14. International Data Transfers

Where Your Data is Stored:

Ra Pay is based in the United States. By using Ra Pay, you consent to:

  • Transfer of your data to the United States
  • Processing and storage of your data in the United States
  • Access to your data by Ra Pay personnel in the United States

We Do Not Transfer Data to Other Countries

Your data is not transferred to countries outside the United States, except:

  • To third-party service providers with Data Processing Agreements (see Section 6)
  • To comply with legal process or government requests
  • As necessary to provide the Service

EU, UK, and Switzerland Residents:

For users subject to GDPR, our payment processor (Stripe) implements appropriate safeguards for international transfers, including Standard Contractual Clauses. See Stripe's Privacy Policy for details.

If you have concerns about international data transfers, contact [email protected].


15. Children's Privacy

Ra Pay is not intended for users under 18 years of age. We do not knowingly collect personal information from minors.

Age Verification:

  • Stripe's KYC process requires users to be 18+ (or the age of majority in their jurisdiction)
  • By using Ra Pay, you represent that you are at least 18 years old
  • If you are a parent/guardian and believe your child has provided us with data, contact [email protected] immediately

If We Discover Minor Data:

If we learn that we have collected data from a user under 18, we will:

  1. Immediately terminate the account
  2. Delete all associated data (subject to legal retention requirements)
  3. Notify the parent/guardian if contact information is available

COPPA Compliance: Ra Pay does not target children under 13 and complies with the Children's Online Privacy Protection Act (COPPA).


16. We Do NOT Sell Your Data

We do not sell, rent, trade, or share your personal information to third parties for marketing purposes.

Your data is shared only:

  • With Stripe for payment processing (see Section 5)
  • With service providers for operational purposes (see Section 6)
  • As required by law (see Section 12)
  • To enforce our Terms of Service

No Marketing Lists: We do not create marketing lists, mailing lists, or advertising audiences based on your data.

No Data Brokers: We do not share your data with data brokers or aggregators.

No Third-Party Marketing: Third parties cannot access your data for advertising purposes.

Minors: We have no actual knowledge of selling the personal information of minors under 16.


17. Cookies and Tracking Technologies

We Do Not Use Cookies or Fingerprinting

Ra Pay is a command-line interface tool. We do not use:

  • HTTP cookies
  • Browser fingerprinting
  • Tracking pixels or beacons
  • Local storage (localStorage, sessionStorage)
  • Device identifiers beyond CLI version and OS type

Our website (rapay.ai) uses Vercel Analytics for anonymous, aggregated page view counts. Vercel Analytics does not use cookies, does not collect personal data, and does not track individual visitors across sessions or devices.

Your CLI interactions with Ra Pay are not tracked across sessions or devices.

Third-Party Tracking: If you click links to external websites in our documentation or emails, those sites may use their own tracking technologies. This Privacy Policy does not apply to third-party websites.


18. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date.

Notification of Material Changes:

For material changes (i.e., changes that expand data collection or reduce privacy protections), we will notify users:

  • Via notice on this page before changes take effect

Continued Use: Continued use of Ra Pay after changes constitutes acceptance of the updated Privacy Policy. If you do not agree with changes, discontinue use of Ra Pay.


19. Contact Us

For questions about this Privacy Policy or to exercise your data rights:

General Privacy Questions & Data Subject Rights Requests:

Legal and Compliance Matters:

Mailing Address:

Ra Pay AI, LLC
c/o Harvard Business Services, Inc.
16192 Coastal Highway
Lewes, Delaware 19958
United States

Ra Pay is based in the United States and does not specifically target EU residents.


20. Governing Law and Jurisdiction

This Privacy Policy is governed by the laws of the State of Delaware, without regard to its conflict of law provisions. Any disputes relating to this Privacy Policy are subject to the Terms of Service Section 17 (Dispute Resolution and Arbitration).


Last Updated: January 2026

Ra Pay AI, LLC is a Delaware limited liability company.

Additional Resources: