Privacy Policy
Effective 2026-09-20 · version 1
This policy explains what ResidualsOS collects when you use ResidualsOS, why, who else sees it, how long we keep it, and what you can ask us to do with it. It is written to match how the product actually works.
1. Who we are and how to reach us
ResidualsOS is operated by ResidualsOS (“we”, “us”), a United States business. The product runs at app.residualsos.com; this site is residualsos.com.
Privacy questions and requests: privacy@residualsos.com. Support: support@residualsos.com. Security reports: security@residualsos.com (see security.txt).
2. Two roles: your account, and your customer's book
ResidualsOS is used by merchant-services ISOs to track residuals and pay partners. That puts us in two different positions, and the law treats them differently:
- We are the controller (or “business”) for the data that describes your relationship with us: your login, your workspace, our invoices to you, usage we meter for billing, and the audit trail of the service.
- We are a processor (or “service provider”) for the data an ISO loads into its workspace: its merchants, its partners, the processor statements it uploads, the tickets and email it logs. The ISO decides what to load and why; we act on its instructions. The ISO is responsible for any notice its partners and merchants are owed, and for having the right to give us that data (see the Terms of Service).
If you are a partner or a merchant of an ISO that uses ResidualsOS and you have a question about your data, the ISO is the right first contact. We will help them answer it.
3. What we collect
Account data. Your name, email address, and password (stored only as a salted hash). If you turn on two-factor authentication: a TOTP secret and hashed recovery codes. Each session records its IP address and browser user agent. Workspace memberships, roles, and invitations you send or receive. When you accept the Terms we record the version, the time, your IP address and browser, and the matching audit-log line, kept as evidence of the agreement for as long as the account exists.
The audit log. An append-only record of what was done in a workspace and by whom: the action, the record it touched, the time, the IP address and user agent, and details such as an invitee’s email, a filename, a partner’s name, or a reason given for a change. Staff can read their workspace’s slice in the app.
Your customer’s business records, loaded by the ISO’s users:
- Merchants: legal and DBA names, merchant IDs, processing volumes, residual and commission figures, up to two contacts (name, email, phone), a business address, and agreed terms.
- Partners: name, email, phone, mailing address, payout terms, and the assignments connecting them to merchants; a bank account for ACH payouts; and, where the tax-form feature is on, a tax profile: legal name, address and taxpayer identification number. Account and taxpayer numbers are encrypted at the field level, only their last four digits readable.
- Processor statements, uploaded or emailed (with the sender’s address), every row as received, and everything the service produces from them.
- Notes, follow-ups, tags and documents staff attach to a merchant or partner.
Tickets and email. Mail sent to a workspace’s intake address (<workspace>@tickets.residualsos.com) becomes a ticket: sender and recipient addresses, subject, plain-text body and mail headers. Email a user forwards or logs against a merchant or partner is stored the same way, only when the other party is one of that account’s contacts; other mail is not kept.
A connected Outlook mailbox (optional). If a user connects Microsoft 365 or Outlook, they grant us delegated permission to read their mail, send mail as them, keep that access without re-prompting, and read their basic profile. We store the mailbox address, display name, encrypted access and refresh tokens, and sync cursors. We read the mailbox to file messages that match an account’s contacts and drop the rest; we send only on the user’s explicit action, from their own mailbox. Disconnecting deletes the tokens.
Usage and operations. Daily counts per workspace of storage used, files, members, active merchant IDs and activity, used for billing and to spot a workspace in trouble. Rate-limit counters keyed by IP address for sign-in and sign-up. Error reports with a stack trace and the route involved. Our hosting provider’s request logs, which can include an email address in a diagnostic line.
Billing. Your plan, workspace size, and the invoices we issue. We do not hold card numbers today; when a payment processor is added it will collect them on its own hosted page and appear on the Subprocessors list.
4. How we use it
- To provide the service: sign you in, keep your workspace separate from every other customer’s, run the calculations, generate statements, send the emails you ask for.
- To keep it secure: authentication, two-factor enforcement, rate limiting, the audit trail, backups, and investigating abuse or an incident.
- To bill you and keep our own financial records.
- To support you when you write to us, and to warn you when something in your workspace needs attention.
- To meet legal obligations and to establish or defend legal claims.
5. What we do not do
- We do not sell personal information, and we do not share it for advertising.
- We run no analytics or tracking scripts on this site or in the product.
- We do not use your data, or your customer’s data, to train machine-learning or AI models.
- We do not read your customer data except to operate the service, to fix a problem you asked us about, or as required by law. Vendor access through the Owner Console is time-boxed, requires a stated reason, is read-only, and is written to your own audit log.
6. Who else sees it
We use a short list of vendors to run the service; they process data only on our instructions. The current list, what each one receives, and where it runs is on the Subprocessors page, which we date and keep current.
Beyond that, we disclose personal information only when the law requires it (we will tell you unless we are legally barred from doing so), to protect the rights or safety of a person or of the service, or to a successor if ResidualsOS is acquired or merges, in which case this policy continues to apply.
8. Security
Each customer’s workspace lives in its own physical database; there is no shared table to query across customers. Traffic is encrypted in transit with TLS, and our hosting provider encrypts every database and file at rest. Two-factor authentication is available to everyone, required for workspace owners and for anyone recording a payment, and may be required for all staff by policy. Access is role-based and enforced on the server. Every significant action is written to an append-only audit log. Databases are backed up nightly and the restore path is drilled monthly. The staff console runs on a separate host behind Cloudflare Access, and any staff access to a workspace is recorded in that workspace’s audit log.
No system is perfectly secure. If you find a vulnerability, please tell us at security@residualsos.com before disclosing it; we will not pursue good-faith researchers. If an incident affects your data we will tell you without undue delay.
9. How long we keep it
- Sessions: seven days, renewed while in use. Invitations: seven days. Sign-in rate-limit counters: about a day.
- Nightly backups: 35 days, then swept. Point-in-time database history at our hosting provider: 30 days. Hosting request logs: about seven days.
- Your workspace’s business records: until you delete them, or the workspace. Uploaded files are removed when you cancel or replace an upload; statements are replaced when regenerated.
- The audit log: kept indefinitely. It is append-only by design and has no delete path.
- Our own records of the account — the invoices, metered usage, backup and support evidence — are kept indefinitely as our books.
Deleting your workspace. A workspace owner can delete the workspace from Settings. That erases every row in the workspace’s database, every uploaded file, statement, document and backup, and every membership and invitation, at once. What remains: the account record marked closed, our invoices and the other records above, the audit log, each person’s own login (usable in other workspaces), the hosting provider’s 30-day database history and short-lived logs, and copies of emails already delivered by our email vendor. Deletion is permanent; the database is not recreated.
Deleting your account. Anyone can delete their own login from Settings → Personal. This removes the login, sessions, two-factor enrollment and memberships, and closes a workspace only that person owns and populates. It is refused while you are the sole owner of a workspace with other members — transfer ownership first.
10. Your rights and choices
Where the law gives you these rights, you can ask to access, correct, export or delete the personal information we hold about you, and you can object to or restrict some uses of it. We do not discriminate against anyone for exercising them.
Much of this you can do in the app: edit your profile, download your merchants, flags and activity as CSV, export payout runs or the whole workspace, download statements (partners can download a year of their own statements as one ZIP), delete documents and prospects, and delete the workspace or your account. For anything else, write to privacy@residualsos.com from the email address on your account; we verify requests against that address and answer within the time the applicable law allows.
Some things we cannot erase on request and will tell you so: the audit log, and locked payout runs, statements and payment records that are your ISO’s financial records. Where a request concerns data an ISO loaded about you, we act on the ISO’s instruction and will pass your request to them.
11. Children
ResidualsOS is a business tool. It is not directed at anyone under 18, and we do not knowingly collect information from children.
12. Where your data is processed
ResidualsOS is a United States business and the service is built for US ISOs. Data is stored and processed on Cloudflare’s network, which is global, and by the other vendors on the Subprocessors page, in the United States. If you use the service from elsewhere, your data will be transferred to and handled in the United States.
13. Changes to this policy
Each version carries a number and an effective date at the top of this page. When we publish a material change we email every workspace owner, and this page shows the date it takes effect. For a change that reduces your rights we set that date at least 30 days out. The previous version is available on request.