Effective Date: August 25, 2026 · Last Updated: August 25, 2026

Privacy Policy

Pactly ("Pactly," "we," "our," or "us") respects your privacy and is committed to protecting your information. This Privacy Policy explains how we collect, use, store, and disclose information when you use the Pactly platform. It applies to users in the United States and is written with California consumer privacy law (CCPA/CPRA) in mind.

1. Information We Collect

Account Information

Name and display name
Email address
Phone number (optional)
Profile photo and preferences
Account role and reputation tier

Transaction Information

Deal titles, descriptions, and agreed terms
Payment amounts and milestone structures
Counterparty name and email
Transaction status and history
Cancellation and dispute records

Payment Data

Payment details are collected and processed by our Payment Provider, Stripe, and its affiliates. Pactly does not store full card numbers or bank account credentials. We receive limited transaction metadata (status, amount, timestamps, last four digits where applicable) needed to operate the Platform.

Communication & Evidence

Chat messages within transaction threads
Uploaded files, images, and documents
Evidence metadata (capture method, timestamps, geo-location when you consent, device hash)
Reactions and presence indicators

Device & Usage Data

IP address and approximate location
Device identifiers and browser type
Operating system and user agent
Login activity and session information
Feature usage and interaction logs

Identity Verification Data

When required for certain transactions, identity verification may be processed through third-party providers such as Stripe Identity. We store verification status and limited results, not the underlying identity documents themselves.

2. How We Use Your Information

We use your information to:

Operate, maintain, and improve the Platform
Facilitate, document, and conditionally release transactions
Verify identity and assess risk
Prevent, detect, and investigate fraud and abuse
Resolve disputes and support audit compliance
Send service, account, and transaction notifications
Comply with legal, regulatory, and Payment Provider obligations
Provide customer and support services

Legal Bases for Processing (CCPA/CPRA)

Under California privacy law, we collect and use your personal information to:

Provide the services you request (performing our contract with you)
Detect and prevent fraud and security incidents
Comply with legal obligations
Maintain a secure, auditable record of transactions
Perform business operations aligned with your expectations as a user

We do not process personal information for the purpose of selling it or sharing it for cross-context behavioral advertising.

3. Sharing of Information

We may share information with the following categories of recipients:

Payment Processors

Stripe and its affiliates, to process payments, payouts, identity verification, and risk checks

Service Providers

Cloud hosting and infrastructure providers
File and media storage providers
Email and notification delivery providers
Analytics and error monitoring tools

Fraud Prevention & Security

Fraud detection and risk assessment partners
Payment networks for chargeback and dispute handling

Legal & Regulatory Disclosures

Law enforcement or government agencies when required by law
To protect our rights, property, or safety
In connection with a legal claim, audit, or regulatory obligation

Business Transfers

In connection with a merger, acquisition, or sale of all or part of our business, information may be transferred subject to the protections of this policy.

We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.

4. Data Retention

We retain personal information only as long as necessary for the purposes described in this policy:

**Account data:** Retained while your account is active and for a reasonable period after closure to resolve disputes and comply with legal obligations.
**Transaction and agreement records:** Retained for the life of the Platform plus seven (7) years to support audit, dispute, and legal compliance.
**Evidence and uploaded files:** Retained for at least seven (7) years, consistent with dispute and fraud-investigation needs.
**Device and usage logs:** Retained up to twenty-four (24) months, except where required longer for security or legal reasons.
**Identity verification results:** Retained for five (5) years or as required by law.

You may request earlier deletion of certain data subject to legal-retention obligations and our legitimate interest in maintaining auditable dispute records.

5. Data Security

We implement reasonable technical, administrative, and physical safeguards designed to protect personal information, including:

Encryption of data in transit and at rest
Access controls limited to authorized personnel
Tamper-evident hashing for locked agreements and evidence
Ongoing security monitoring and incident response

No system can guarantee absolute security. You are responsible for protecting your account credentials and enabling available security features such as two-factor authentication.

6. Data Breach Notification

In the event of a security breach affecting your personal information, we will take reasonable steps to investigate, contain, and remediate the incident.

Where required by applicable law, we will notify affected users and relevant authorities without undue delay, using contact information on file or through in-app and email notices.

7. Children's Data

Pactly is not intended for individuals under eighteen (18) years of age, and we do not knowingly collect personal information from children.

If you believe a minor has provided us personal information, please contact support@pactlysecure.com and we will take steps to delete such information.

8. Your California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the right to:

Know what personal information we collect and how it is used
Request deletion of your personal information
Request correction of inaccurate personal information
Opt out of the sale or sharing of personal information
Limit the use of sensitive personal information
Non-discrimination: we will not discriminate against you for exercising your privacy rights

**We do not sell your personal information**, and we do not share it for cross-context behavioral advertising, so there is no sale or sharing to opt out of. You do not need to submit an opt-out request.

**To exercise your rights**, email privacy@pactlysecure.com with "California Privacy Request" in the subject line. We will verify your identity before responding. Authorized agents may submit requests with written permission.

We will respond to verified requests within forty-five (45) days, extended as permitted by law.

9. Do Not Track

Some browsers offer a "Do Not Track" signal. Because there is no consistent industry standard for interpreting these signals, Pactly does not currently alter its data practices in response to them. We limit tracking to what is necessary to operate, secure, and improve the Platform, as described in this policy.

10. Cookies and Similar Technologies

We use cookies, local storage, and similar technologies to:

Authenticate your session and keep you signed in
Remember preferences such as display theme
Operate core platform functionality

We do not use cookies for cross-context behavioral advertising. See our Cookie Policy for details on the specific technologies used and how to manage them.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will indicate changes by updating the "Last Updated" date and, for material changes, provide notice through the Platform or by email.

Continued use of the Platform after changes become effective constitutes acceptance of the updated policy.

12. Contact

For privacy questions or to submit a privacy request:

Pactly — Privacy Team

Email: privacy@pactlysecure.com

Support: support@pactlysecure.com

Mailing address: [Registered Business Address]