Attest
Gateway Report Support

Data Handling + Retention Statement

Effective: 2026-08-26 Applies to: Attest, an ECTD product. Companion to the Privacy Policy — this document covers the operational detail of where data lives, how long, and who can reach it.

---

1. Data we hold, by category

CategoryExamplesWhere it livesRetention
IdentityBuyer name, email, business name, countrySupabase (ap-southeast-2, Sydney)7 years from last transaction (tax record obligation)
Purchase recordsStripe order ID, amount, currency, payment timestampSupabase + Stripe7 years
Intake submissionsService description, endpoint URL, risk category, pricing intent, supplementary fieldsSupabase2 years after delivery, then deleted or anonymised
Deliverable copiesThe PDF + JSON files we sent youSupabase2 years after delivery
Ledger eventsAppend-only log of purchase.created, deliverable.sent, refund.issued eventsSupabase ledger_events table7 years
Refund requestsCheckout Session ID or receipt email, reason, status, timestampsSupabase capture_refund_requests table2 years after resolution unless a longer legal retention period applies
Server logsIP, timestamp, requested URL, response codeVercel30 days
Card dataPAN, CVV, expiryNever on Attest infrastructure — handled entirely by StripeStripe's retention

2. Where data is stored, by provider

Stripe (payments + checkout)

Stripe processes all card payments and hosts checkout under ECTD. We never see card numbers, CVVs, or full payment instruments. Stripe holds the cardholder data under its own PCI-DSS Level 1 compliance and global infrastructure.

Supabase (operational data, Sydney AU)

The Attest spend ledger runs on Supabase, project agentstack-ledger, region ap-southeast-2 (Sydney). Tables include purchases, intake_submissions, deliverables, ledger_events, refunds, Capture claims, and Capture refund requests. Row-Level Security is enabled on every table. The service-role key is held only in the Attest serverless function environment and is not exposed in the repo.

Vercel (hosting)

The Attest website and webhook endpoint run on Vercel. Vercel handles TLS termination (Let's Encrypt) and serves the static + serverless surface. Vercel sees request metadata; it does not see Stripe card data and does not have direct access to Supabase service-role keys (those are passed at function invocation only).

3. Who can access what

  • Jason (sole operator) — has access to all categories above for support, fulfilment, and operational purposes.
  • Delegated reviewers (when introduced) — receive only the intake fields and AI-drafted deliverable needed for review of a specific order. Access is per-order, time-limited, and logged.
  • Third-party providers (Stripe, Supabase, Vercel) — access only as required to operate their service, per their own contracts and privacy notices.
  • Subcontractors or AI providers — intake data may pass through AI tooling (e.g. an LLM API) to draft the deliverable. We use providers that contractually do not train on or retain customer prompt data beyond short transient processing windows. We do not feed customer intake into providers that train on user content.

4. Security practices

  • TLS in transit everywhere (Let's Encrypt for getattest.com.au).
  • Row-Level Security on every Supabase table.
  • Service-role key held only in Vercel environment variables (encrypted at rest by Vercel) and rotated if a leak is suspected.
  • Webhook integrity verified by Stripe signature (STRIPE_WEBHOOK_SECRET).
  • No card or PAN data ever touches Attest infrastructure.
  • No customer data is stored on Jason's personal devices outside the operational scope above.

5. Data subject rights (Australian Privacy Principles)

You can ask:

  • What information we hold about you (access request)
  • That we correct it (correction request)
  • That we delete identifiable copies, except records we are legally required to retain (deletion request)

Make the request via the support channels listed at getattest.com.au/support. We aim to action verified requests within 30 days.

6. Data breach response

If we become aware of an unauthorised disclosure of personal information likely to result in serious harm:

  • We will assess within 30 days per the Notifiable Data Breaches scheme (Privacy Act 1988 (Cth) Part IIIC)
  • We will notify the Office of the Australian Information Commissioner and affected individuals where the scheme requires
  • We will take immediate operational steps to contain, investigate, and remediate

7. International transfers

Stripe and Vercel operate global infrastructure. Some payment or request metadata may transit through, or be processed in, jurisdictions outside Australia (typically the United States and the EU). By using Attest you consent to these transfers as a necessary part of using the service.

8. Changes

We will update this document as our infrastructure changes. The Effective date at the top reflects the current version.

9. Contact

Attest, an ECTD product, Queensland, Australia. Contact runs through the support channels listed at getattest.com.au/support.

Attest by ECTD · getattest.com.au
Privacy Terms Refunds Acceptable use AI disclaimer Data handling Support No custody