Data Retention Policy
Latest Revision: September 10, 2026
This policy outlines the requirements and controls/procedures Straddle Payments, Inc has implemented to manage the retention and deletion of customer data.
Policy
We retain your Personal Data as long as we are providing the Services to you or our Business Users (as applicable) or for a period during which we reasonably anticipate providing the Services. Even after we stop providing Services directly to you or a Business User with which you are doing business, and even if you close your Straddle account or complete a transaction with a Business User, we may retain your Personal Data:
- to comply with our legal and regulatory obligations.
- to enable fraud monitoring, detection and loss prevention activities.
- to comply with our tax, accounting, and financial reporting obligations
- where required by our contractual commitments to our financial partners (and where data retention is mandated by the payment methods you used).
In cases where we keep Personal Data, we do so in accordance with any limitation periods and records retention obligations that are imposed by applicable law.
As a Third-party Sender of ACH transactions, Straddle is bound to Nacha’s data retention rules for ODFIs and Third-Party Service Providers as defined in the Nacha Operating Rules. The specific rule related to record retention is Article One, Subsection 1.9 - 1.2.2, "Retention of Records by Originating Depository Financial Institutions and Third-Party Service Providers."
According to the Nacha Operating Rules, ODFIs and Third-Party Service Providers must retain records for a period of six years from the termination or expiration of the agreement between the ODFI and the Third-Party Service Provider. This retention period applies to records that would enable an audit of the Third-Party Service Provider's compliance with the terms of the agreement and the Rules.
You can find more information in the Nacha Operating Rules, which can be purchased from the Nacha website: https://www.nacha.org/rules
Retention Schedule
The periods below apply to the categories of data we hold. Where more than one period applies to the same record, the longest period applies. Periods that run from the date of receipt or observation are applied on a rolling basis, so data older than the period is deleted on an ongoing basis.
| Data category | Retention period | Basis |
|---|---|---|
| Bank-sourced account and payment history for a linked financial account (transactions posted, dates, amounts, returns) | No longer than 24 months from the date we receive it | Purpose limitation — account verification, payment return-risk assessment and fraud prevention |
| Balance observations for a linked financial account, including balances collected on a periodic basis when no payment is pending | No longer than 24 months from the date of the observation | Purpose limitation — payment return-risk assessment and fraud prevention |
| Balance at the time of a payment | Retained with the payment record | Payment record; dispute and return defense |
| Risk scores and derived features produced from the categories above | Retained with the payment record to which they relate | Audit, dispute and return defense |
| Payment records, authorization records and related transaction records | 6 years | Nacha Operating Rules; Nacha Authorization Requirements set a 2-year minimum from the date of the last payment initiated under an authorization |
| Express Consent records for Bridge End Users | The Term plus at least 24 months | Straddle Bridge Terms, Section 2.2 |
| Identity verification data and identification document images | For the period necessary to complete verification and to satisfy BSA/AML recordkeeping obligations, and no longer than 5 years after the verification | BSA/AML recordkeeping |
| Biometric templates generated to compare a photograph to an identification document | Deleted once the verification purpose is satisfied, and in any event within the period required by applicable biometric privacy law | State biometric privacy law |
| Straddle Account records for a business user | 6 years from the date the account data enters the expired state, as described below | Nacha Operating Rules |
Aggregated, de-identified and anonymized data derived from any category above is not attributable to an individual and is not subject to these periods. We may retain and use it for as long as applicable law permits.
The 6-year period described below applies to Straddle Account records and payment records. It does not extend the periods stated in the schedule above for bank-sourced account and payment history or balance observations.
Customer data is retained for as long as the account is in active status. Data enters an “expired” state when the account is voluntarily closed. Expired account data will be retained for 6 years. After this period, the account and related data will be removed. Customers that wish to voluntarily close their account should download their data manually prior to closing their account.
If a customer account is involuntarily suspended, then there is a 6 years grace period during which the account will be inaccessible but can be reopened if the customer meets their payment obligations and resolves any terms of service violations.
If a customer wishes to manually backup their data in a suspended account, then they must ensure that their account is brought back to good standing so that the user interface will be available for their use. After 6 years, the suspended account will be closed and the data will enter the “expired” state. It will be permanently removed 6 years thereafter (except when required by law to retain).
Denver, CO