LEGAL / PRIVACY

Privacy Policy

This policy explains what we collect, why, and who sees it — for you as our customer, and for your customers whose invoices and payments flow through Paradox.

Last updated August 8, 2026

1. What we collect

  • /Account data — your name, business name, email, phone, billing address, and an encrypted password hash.
  • /Mobile numbers and text-message consent — when you or your customers opt in to texts, the mobile number and the date and source of consent (a checkbox on a payment page, or consent you recorded on a customer profile).
  • /Business data you enter — your customers, invoices, subscriptions, payment pages and email templates.
  • /Payment metadata — amounts, dates, card brand, last four digits, expiry, authorization codes and settlement status returned by your gateway. Never full card numbers: card entry happens inside Fiserv's secure frame and only a token reaches Paradox.
  • /Gateway credentials — your CardPointe merchant ID and API credentials, encrypted at rest; the API password is write-only and is never displayed back.
  • /Usage basics — sign-in events and an audit trail of significant account actions.

2. What we use it for

To run the service you asked for: charging cards on your instruction, sending invoices, receipts and reminders from your business, reconciling your ledger against settlement, and billing your Paradox subscription. We do not sell personal information, we do not use your customers' data for advertising, and we do not train AI models on your data.

3. Who we share it with

Only the parties needed to operate the service:

  • /Fiserv / CardConnect — your own gateway, which processes the payments you initiate.
  • /Twilio SendGrid — delivers the transactional emails you send (invoices, receipts, reminders).
  • /Twilio — delivers the text messages sent to customers who opted in.
  • /Authorities, if the law genuinely requires it — and we'll tell you unless we're legally prevented.

All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

4. Cookies and sessions

Paradox uses a single encrypted session cookie to keep you signed in, and a local preference for light/dark mode. We use Google Tag Manager for visitor analytics on our website; we never feed it your customers' data or anything from inside your account.

5. Text messages (SMS)

If you or your customers opt in to text messages, we use the mobile number solely to send the transactional messages that were requested — payment receipts, links to view and pay an invoice, payment reminders, and notices about a subscription the recipient signed up for — sent by Paradox Solutions on behalf of the business involved. Consent is collected through an unchecked-by-default checkbox at the point of payment, or recorded by a business for a customer who asked to receive texts. Message frequency varies. Message and data rates may apply.

Reply STOP to any message to opt out at any time, or HELP for help. Opt-outs take effect immediately and apply across every business on the platform.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All other categories of sharing described in this policy exclude text-messaging originator opt-in data and consent; this information will not be shared with any third parties. Mobile numbers are shared only with our messaging provider to the extent necessary to deliver the messages you requested. The full program terms are in our Mobile Messaging Terms.

6. Retention and deletion

We keep your data while your account is active. Transaction records may be retained after closure where financial-record laws require it. Otherwise, close your account and ask for deletion via the contact page and we'll erase your data within 30 days.

7. Security

All traffic is encrypted in transit with TLS. Gateway credentials are encrypted at rest with AES-256; passwords are stored only as salted hashes. Card numbers never reach our systems by design. No internet service can promise perfection — if we ever learn of a breach affecting your data, we will notify you promptly with what we know and what we're doing.

8. Your rights

You can access, correct, export or delete your personal information. California residents have these rights under the CCPA/CPRA; we honor the same rights for everyone regardless of where you live. Write to us via the contact page, email [email protected], or mail Paradox Solutions Inc., 18524 Sophia Ln, Tarzana, CA 91356 — we'll respond within 30 days.