← Trust & security

Data Processing Agreement

This DPA forms part of the agreement between the merchant (“Controller”) and Pine Creative Inc. o/a Thaw Payments (“Processor”) for the processing of personal data.

1. Roles & subject matter

The Controller determines the purposes and means of processing; the Processor processes personal data only on the Controller's documented instructions. Subject matter: recovering failed and at-risk subscription payments on the Controller's behalf.

2. Duration

Processing continues for the term of the service. On termination or disconnection, data is retained for 90 days and then deleted, unless the Controller requests earlier deletion.

3. Nature & purpose of processing

Detecting revenue leaks, generating and sending recovery communications, executing compliant payment retries, attributing recoveries, and billing the Processor's fee.

4. Categories of data subjects & personal data

Data subjects: the Controller's end customers. Personal data: name, email, subscription and plan details, payment status and metadata, and card tokens/metadata (never full card numbers — see §7).

5. Controller obligations

The Controller warrants it has a lawful basis to share end-customer data and to instruct the recovery communications sent on its behalf.

6. Processor obligations

The Processor will: process only on documented instructions; ensure personnel are bound by confidentiality; implement the security measures in §8; assist with data-subject requests; and not sell data or use it to train models.

7. Card data

All cardholder data processing remains with Stripe (PCI DSS Level 1). The Processor never stores or has access to full card numbers.

8. Security measures

Row-level data isolation per merchant; server-only secrets; encryption in transit (TLS) and at rest; least-privilege team roles; and an immutable audit log of all actions.

9. Subprocessors

The Controller authorizes the subprocessors listed on the Trust & Security page (Stripe, Supabase, Vercel, Resend, Anthropic, Google Workspace). The Processor remains liable for their performance and will give notice of changes.

10. Data-subject rights

The Processor will assist the Controller in responding to access, correction, deletion, and objection requests, including honoring end-customer unsubscribes and suppression.

11. Personal data breach

The Processor will notify the Controller without undue delay after becoming aware of a personal data breach and provide information reasonably needed to meet the Controller's notification obligations.

12. Deletion & return

On request or at termination, the Processor will delete or return personal data (Controller's choice), subject to the 90-day retention window and any legal retention requirement.

13. Audits

The Processor will make available information necessary to demonstrate compliance and allow for reasonable audits, including via third-party reports once available (SOC 2).

14. International transfers

Where data is transferred across borders, the parties rely on an appropriate transfer mechanism (e.g. Standard Contractual Clauses) as applicable.

Questions: privacy@thawpayments.com.