Privacy
This page is an engineering checklist for the pilot, not a lawyer-signed privacy policy, data processing agreement, or certification (HIPAA, PCI DSS, SOC 2, ISO 27001, GDPR, Qatar PDPL, or PH Data Privacy Act).
- Tenant data is scoped by the signed-in user's tenant, never by a request field.
- Administrators can export a tenant package, file deletion requests that deactivate rather than purge posted money, and review access and support grants from Settings → Privacy & data after sign-in.
- Logs may include tenant and user ids plus a request id. Passwords and tokens are redacted.
- Optional error tracking (Sentry) is disabled unless an operator sets a DSN.
- Do not load production customer data into the demo tenant.