Testing environment — not for live payments. Data may be reset at any time.
Syde Rail Syde Rail ← Home

Privacy Policy

Last updated July 31, 2026

Draft. This policy is a working draft for the testing phase and should be reviewed by legal counsel before live merchant use.

Who we are

Syde Rail ("we", "us") provides a payments platform and a companion browser extension that lets merchants take card, terminal, ACH, and pay-by-link payments inside the web applications they already use. This policy explains what we collect and why.

Card data — what we do NOT store

We never receive or store full payment card numbers. Card details are entered into a hosted form supplied by the payment processor (e.g. Stripe, Authorize.Net, NMI, Clover, Fortis, Dejavoo) and are tokenized in the processor's own systems. Our platform operates at PCI DSS SAQ A scope — card data does not touch the browser extension, the merchant's host application, or our servers.

Information we process

To operate the service we process: account and contact details for partners, agents, and merchants; merchant business details and (encrypted) processor credentials; transaction metadata (amount, status, timestamps, last-four and card brand returned by the processor); customer details a merchant chooses to charge (name, email, phone) — including details read from the page the cashier is working on, used only to populate the payment form; and device pairing identifiers for each browser running the extension.

The browser extension

The extension runs in the browser side panel alongside the merchant's other software. With the merchant's installation, it can read fields on the current page to pre-fill customer and amount details, and write a receipt or result back into the host application after a charge. It accesses page content only when the cashier initiates an action, and only to perform the payment workflow. It does not track browsing history or sell data.

How we use information

We use the information to process payments, provide the agent/partner/merchant dashboards, attribute transactions to the correct merchant and device, prevent fraud and misuse, and provide support. We do not sell personal information.

Sharing

We share information with the payment processor selected by each merchant (to complete charges), and with infrastructure providers that host our application and database under contract. We may disclose information where required by law.

Data retention

We retain account and transaction records for as long as needed to provide the service and to meet legal, tax, and dispute-resolution obligations, then delete or anonymize them.

Security

Processor credentials are stored encrypted. Access to merchant data is restricted by role and tenant. The connection between the extension and our servers uses HTTPS.

Your choices

Merchants and partners may request access to, correction of, or deletion of their data by contacting us. A paired device can be unpaired at any time from the extension's settings, which clears its stored token.

Contact

Questions about this policy? Contact us at privacy@syderail.com.