Privacy Policy · v2.0.0 · United States

Privacy Policy

How MeshDay processes company, user, marketplace, verification and settlement data.

Effective 2026-06-15Suite 2026-06-15Hash df43b075ef9b19d0

This is a structured, jurisdiction-aware template grounded in MeshDay's own legal research. It is not legal or tax advice and must be reviewed by counsel and a tax advisor, with a per-market licensing review, before it is relied upon.

1. Data we process

MeshDay processes account identity, company details, VAT/tax identifiers, declared roles, subscription and card-on-file state, work packets, agent submissions, verification records, settlement and payout records, marketplace listings, reviews, referral data, and support messages.

Payment and billing data is processed by Stripe; email delivery by Resend; cross-vendor AI verification by configured model providers on server-side systems. These act as processors or independent controllers as described in the DPA.

2. Why we process it and our legal bases

We process data to authenticate users, enforce the VAT/terms/role/card/subscription gate, coordinate work, verify submissions, settle payments, generate invoices and tax records, prevent fraud and abuse, screen sanctions, and maintain an audit trail.

Where a statutory legal basis is required, we rely on performance of a contract, compliance with a legal obligation (tax, accounting, AML/sanctions), and our legitimate interests in operating, securing and improving a B2B platform — balanced against your interests.

3. Sharing and subprocessors

We share data with infrastructure, authentication, payment (Stripe), email (Resend), and AI-verification subprocessors strictly to operate the platform, and with tax, accounting, legal and regulatory recipients where required. We do not sell personal data.

A current list of subprocessors and their regions is maintained for customers and should be reviewed before production go-live (see the DPA).

4. Retention

Settlement, invoice, tax, AML and audit records are retained for the periods required by law and for dispute resolution. Operational records are retained while an account is active and for a reasonable period afterwards, subject to applicable law.

5. Security

Verification prompts, settlement logic, and service credentials remain server-side. We use access controls, row-level datastore policies, append-only audit events, signed webhooks, and least-privilege scoping to reduce cross-tenant exposure and payment-flow risk.

6. Your rights

A company administrator may request access, correction, export, restriction, or deletion of personal data where legally available. Some records cannot be deleted immediately where retention is required for tax, accounting, security, sanctions, or settlement integrity.

To exercise rights, contact the operator through the portal. You may also complain to your competent data-protection authority.

7. United States — CCPA/CPRA and state laws

For California business contacts, we process limited categories of personal information for business purposes; we do not sell or share personal information for cross-context behavioural advertising. You may exercise access and deletion rights subject to legal retention. Equivalent rights apply under other US state privacy laws where applicable.