Privacy — PCI DSS products
What is stored when you run a check or subscribe to the evidence ledger, and when it is deleted.
What a free check stores
Nothing tied to you. A free check is answered from the request and the result is returned to you; no account exists and none is created. To understand whether the service is useful, we keep only aggregate UTC-day counts for a closed list of events such as page views, completed checks, offers, sample views, and checkout redirects. Those counters contain no IP address, cookie, target, result, referrer, account, or cross-request identifier and are deleted after 400 days. Ordinary web server logs still apply.
What paid products store
For every paid product we retain Polar checkout, order, product, and subscription identifiers where applicable; the amount, currency, and payment time; and delivery, cancellation, and refund status. A one-time remediation artifact and its integrity digest are retained for 30 days after delivery so the same paid return can recover it without generating a different result. The artifact may include the payment-page URL or sending domain you supplied.
What the evidence ledger stores
The page URL you asked us to monitor, the host, the authorized script domains you supplied, and for each evaluation a timestamp, a digest of what was observed, a severity, and the hash chain that makes the record verifiable. The most recent observation is kept so the next evaluation has something to compare against, and is overwritten each time.
Data the checks do not request or retain
The checks do not request card numbers, customer names, email addresses, or payment details. Do not submit them, credentials, authenticated DOM state, or private source in a pasted document. A free request can contain a public page URL or the raw HTML you deliberately paste; the application processes that request to return the result but does not persist the raw HTML or free result. Ordinary web-server logs still apply as described above. A ledger report credential is stored only as a keyed hash, and raw private delivery credentials are not stored. A copy of our database therefore does not grant access to a report. Repeating the same verified paid return can recover its credential while the underlying purchase and monitor still exist.
Deletion
When a subscription ends, the monitor and its history are deleted 30 days later. The delay is deliberate: it gives you time to ask for the evidence if an assessment is still underway. A new subscription creates a new monitor; it does not cancel deletion of a monitor whose entitlement ended. One-time remediation content is removed 30 days after delivery. Transaction identifiers and fulfillment/refund audit state remain after content deletion so the service can prevent duplicate delivery and refunds.
Processors
Polar processes payment as merchant of record and holds the billing relationship. Hosting is on our own server. Backups taken by the hosting provider may retain data longer than the window above.
Requests
Email qi@toledotechnologies.com to ask what is held about a monitor you purchased, or to have it deleted before the window closes.
These pages cover Tessera's PCI DSS products.