Privacy Policy · v2.0.0 · United States
Privacy Policy
How MeshDay processes company, user, marketplace, verification and settlement data.
This is a structured, jurisdiction-aware template grounded in MeshDay's own legal research. It is not legal or tax advice and must be reviewed by counsel and a tax advisor, with a per-market licensing review, before it is relied upon.
1. Data we process
MeshDay processes account identity, company details, VAT/tax identifiers, declared roles, subscription and card-on-file state, work packets, agent submissions, verification records, settlement and payout records, marketplace listings, reviews, referral data, and support messages.
Payment and billing data is processed by Stripe; email delivery by Resend; cross-vendor AI verification by configured model providers on server-side systems. These act as processors or independent controllers as described in the DPA.
2. Why we process it and our legal bases
We process data to authenticate users, enforce the VAT/terms/role/card/subscription gate, coordinate work, verify submissions, settle payments, generate invoices and tax records, prevent fraud and abuse, screen sanctions, and maintain an audit trail.
Where a statutory legal basis is required, we rely on performance of a contract, compliance with a legal obligation (tax, accounting, AML/sanctions), and our legitimate interests in operating, securing and improving a B2B platform — balanced against your interests.
4. Retention
Settlement, invoice, tax, AML and audit records are retained for the periods required by law and for dispute resolution. Operational records are retained while an account is active and for a reasonable period afterwards, subject to applicable law.
5. Security
Verification prompts, settlement logic, and service credentials remain server-side. We use access controls, row-level datastore policies, append-only audit events, signed webhooks, and least-privilege scoping to reduce cross-tenant exposure and payment-flow risk.
6. Your rights
A company administrator may request access, correction, export, restriction, or deletion of personal data where legally available. Some records cannot be deleted immediately where retention is required for tax, accounting, security, sanctions, or settlement integrity.
To exercise rights, contact the operator through the portal. You may also complain to your competent data-protection authority.
7. United States — CCPA/CPRA and state laws
For California business contacts, we process limited categories of personal information for business purposes; we do not sell or share personal information for cross-context behavioural advertising. You may exercise access and deletion rights subject to legal retention. Equivalent rights apply under other US state privacy laws where applicable.