Data Retention Policy

Latest Revision: September 10, 2026

This policy outlines the requirements and controls/procedures Straddle Payments, Inc has implemented to manage the retention and deletion of customer data.

Policy

We retain your Personal Data as long as we are providing the Services to you or our Business Users (as applicable) or for a period during which we reasonably anticipate providing the Services. Even after we stop providing Services directly to you or a Business User with which you are doing business, and even if you close your Straddle account or complete a transaction with a Business User, we may retain your Personal Data:

  • to comply with our legal and regulatory obligations.
  • to enable fraud monitoring, detection and loss prevention activities.
  • to comply with our tax, accounting, and financial reporting obligations
  • where required by our contractual commitments to our financial partners (and where data retention is mandated by the payment methods you used).

In cases where we keep Personal Data, we do so in accordance with any limitation periods and records retention obligations that are imposed by applicable law.

As a Third-party Sender of ACH transactions, Straddle is bound to Nacha’s data retention rules for ODFIs and Third-Party Service Providers as defined in the Nacha Operating Rules. The specific rule related to record retention is Article One, Subsection 1.9 - 1.2.2, "Retention of Records by Originating Depository Financial Institutions and Third-Party Service Providers."

According to the Nacha Operating Rules, ODFIs and Third-Party Service Providers must retain records for a period of six years from the termination or expiration of the agreement between the ODFI and the Third-Party Service Provider. This retention period applies to records that would enable an audit of the Third-Party Service Provider's compliance with the terms of the agreement and the Rules.

You can find more information in the Nacha Operating Rules, which can be purchased from the Nacha website: https://www.nacha.org/rules

Retention Schedule

The periods below apply to the categories of data we hold. Where more than one period applies to the same record, the longest period applies. Periods that run from the date of receipt or observation are applied on a rolling basis, so data older than the period is deleted on an ongoing basis.

Data categoryRetention periodBasis
Bank-sourced account and payment history for a linked financial account (transactions posted, dates, amounts, returns)No longer than 24 months from the date we receive itPurpose limitation — account verification, payment return-risk assessment and fraud prevention
Balance observations for a linked financial account, including balances collected on a periodic basis when no payment is pendingNo longer than 24 months from the date of the observationPurpose limitation — payment return-risk assessment and fraud prevention
Balance at the time of a paymentRetained with the payment recordPayment record; dispute and return defense
Risk scores and derived features produced from the categories aboveRetained with the payment record to which they relateAudit, dispute and return defense
Payment records, authorization records and related transaction records6 yearsNacha Operating Rules; Nacha Authorization Requirements set a 2-year minimum from the date of the last payment initiated under an authorization
Express Consent records for Bridge End UsersThe Term plus at least 24 monthsStraddle Bridge Terms, Section 2.2
Identity verification data and identification document imagesFor the period necessary to complete verification and to satisfy BSA/AML recordkeeping obligations, and no longer than 5 years after the verificationBSA/AML recordkeeping
Biometric templates generated to compare a photograph to an identification documentDeleted once the verification purpose is satisfied, and in any event within the period required by applicable biometric privacy lawState biometric privacy law
Straddle Account records for a business user6 years from the date the account data enters the expired state, as described belowNacha Operating Rules

Aggregated, de-identified and anonymized data derived from any category above is not attributable to an individual and is not subject to these periods. We may retain and use it for as long as applicable law permits.

The 6-year period described below applies to Straddle Account records and payment records. It does not extend the periods stated in the schedule above for bank-sourced account and payment history or balance observations.

Customer data is retained for as long as the account is in active status. Data enters an “expired” state when the account is voluntarily closed. Expired account data will be retained for 6 years. After this period, the account and related data will be removed. Customers that wish to voluntarily close their account should download their data manually prior to closing their account.

If a customer account is involuntarily suspended, then there is a 6 years grace period during which the account will be inaccessible but can be reopened if the customer meets their payment obligations and resolves any terms of service violations.

If a customer wishes to manually backup their data in a suspended account, then they must ensure that their account is brought back to good standing so that the user interface will be available for their use. After 6 years, the suspended account will be closed and the data will enter the “expired” state. It will be permanently removed 6 years thereafter (except when required by law to retain).

www.straddle.com

Denver, CO

compliance@straddle.com