PineTree Platform Compliance, Regulatory Disclosure & Infrastructure Policy Effective Date: July 17, 2026 Last Updated: July 17, 2026 Purpose and Status of This Policy --------------------------------- This policy describes PineTree Payments LLC's current operating model, infrastructure boundaries, compliance approach, and allocation of responsibilities among PineTree, merchants, customers, payment providers, technology vendors, card networks, blockchain networks, and other third parties. It is intended to provide a clear public explanation of how the PineTree platform is designed and operated. This policy is not a legal opinion, regulatory license, audit report, certification, guarantee of compliance, or representation that every law or regulatory framework listed below applies to every PineTree service. Regulatory treatment depends on the facts, funds flow, jurisdictions, services enabled, provider relationships, and applicable law. PineTree may revise its operating model or obtain additional approvals if its activities or legal obligations change. Important: PineTree is a technology and payment-orchestration platform. Connected providers, financial institutions, payment processors, wallet infrastructure providers, and blockchain networks may perform regulated functions under their own licenses, approvals, contracts, and compliance programs. Merchants remain responsible for their own legal and regulatory obligations. 1. Platform Overview -------------------- PineTree provides software infrastructure that allows merchants, platforms, and developers to create, route, monitor, and report payments through a unified interface. Depending on configuration and availability, the platform may include PineTree POS, hosted checkout, payment links, merchant dashboards, provider connection tools, wallet and balance visibility, compatible terminal workflows, commerce connectors, developer APIs, webhooks, reporting, and related support features. PineTree supports multiple payment methods and provider relationships, including card payments, compatible in-person terminal transactions, stablecoin and digital-asset payments, Bitcoin Lightning payments, and supported online-commerce connections. PineTree is designed to help a merchant use compatible providers and hardware without requiring the merchant to rebuild its payment stack solely to use PineTree. 2. PineTree's Role ------------------ PineTree is structured primarily as a software, orchestration, user-interface, and reporting provider. PineTree is not a bank, card network, acquiring bank, issuing bank, broker-dealer, securities exchange, investment adviser, or tax adviser. PineTree does not provide investment recommendations, legal advice, accounting advice, or guarantees concerning the value, tax treatment, legality, or future performance of any payment method or digital asset. Unless PineTree expressly agrees otherwise in a separate written agreement, PineTree does not itself underwrite merchants, issue payment cards, acquire card transactions, maintain customer deposit accounts, exchange securities, guarantee settlement, or custody merchant or customer funds. The actual regulatory classification of any service depends on the service's facts and operation and cannot be determined solely by this policy. Nothing on the PineTree website or platform should be interpreted as an endorsement, approval, license, or certification by a government agency, card network, blockchain foundation, provider, or regulator. 3. Provider-Led Processing, Underwriting, and Settlement -------------------------------------------------------- PineTree connects with compatible third-party providers that may supply card processing, acquiring, gateway, terminal, wallet, digital-asset, blockchain, custody, settlement, conversion, fraud, identity, compliance, or other infrastructure. Depending on the service, a merchant may connect an existing provider account or establish a provider account, connected account, sub-account, gateway profile, wallet account, terminal location, or similar provider-controlled relationship. Providers may be responsible for activities including: - Merchant onboarding, underwriting, and approval decisions. - Know Your Business (KYB), Know Your Customer (KYC), identity verification, and beneficial-owner review. - Anti-money-laundering, fraud, sanctions, and transaction-risk controls required for the provider's services. - Payment authorization, acquiring, processing, custody, conversion, reserves, settlement, payout, refunds, disputes, and chargebacks. - Provider account restrictions, holds, limits, denials, suspensions, and termination decisions. - Compliance with card-network, banking, licensing, financial-services, and other rules applicable to the provider. PineTree may facilitate technical onboarding, display provider status, transmit information authorized by the merchant, and coordinate provider workflows. PineTree does not control or guarantee a provider's approval, availability, compliance decisions, pricing, settlement timing, reserves, risk rules, or account actions. 4. Platform Architecture and Separation of Responsibilities ----------------------------------------------------------- PineTree uses a layered architecture intended to separate user interfaces, platform business logic, provider-specific integrations, and records. The principal design pattern is: user interface to PineTree API to PineTree Engine to provider adapter to PineTree database and the applicable provider or payment network. The PineTree Engine is the orchestration layer responsible for functions such as payment creation, provider selection, fee calculation, transaction-state management, event processing, idempotency, ledger updates, and normalized reporting. Provider adapters isolate provider-specific credentials, APIs, webhooks, statuses, and error handling from the rest of the platform. PineTree's user interfaces are designed not to call external payment providers directly. Payment requests and provider actions are routed through controlled API and engine layers. PineTree's database serves as the platform's operational source of truth, while the relevant provider, card network, wallet, or blockchain remains authoritative for its own processing, settlement, and network records. This architecture supports traceability and consistency but does not eliminate merchant, provider, or PineTree obligations under applicable law or industry rules. 5. Card Payments and PCI Responsibilities ----------------------------------------- Card payments may be supported through connected processors, gateways, hosted fields, secure iframes, provider software development kits, payment elements, compatible terminals, or tokenized payment methods. PineTree is designed to avoid directly receiving or storing complete payment-card account numbers, card verification values, PIN data, magnetic-stripe data, or other sensitive authentication data where provider-hosted and tokenized methods are available. PineTree may receive limited card-related metadata, such as a provider token, payment-method identifier, card brand, last four digits, expiration metadata, transaction result, authorization status, processor reference, dispute status, or terminal reference. Such information may be used for operational visibility, support, reconciliation, and reporting. Use of a third-party processor or validated terminal does not automatically eliminate all Payment Card Industry Data Security Standard (PCI DSS) responsibilities. Merchants must determine their own PCI scope, use approved integrations, maintain required policies, secure their websites and devices, verify provider compliance where required, and complete any applicable validation requested by their provider, acquiring bank, or card network. Merchants may not use PineTree fields, notes, support tickets, APIs, logs, or other general-purpose interfaces to submit complete card numbers, card verification values, PINs, passwords, or other prohibited payment credentials. 6. Terminals, Tap-to-Pay, and Hardware -------------------------------------- PineTree may support compatible payment terminals, readers, browser-based terminal controls, tablet workflows, or device-based tap-to-pay features through connected providers. Hardware availability, certification, functionality, card-network support, operating-system requirements, geographic coverage, and merchant eligibility depend on the applicable provider, manufacturer, device, and certification status. Merchants are responsible for obtaining approved hardware where required, maintaining physical device security, preventing tampering, installing updates, following provider instructions, controlling staff access, and promptly reporting lost, stolen, compromised, or altered devices. PineTree does not guarantee that an existing terminal is compatible unless the terminal and provider configuration are specifically supported. 7. Digital Assets, Stablecoins, and Bitcoin Lightning ----------------------------------------------------- PineTree may support digital-asset payment rails such as Base Pay, Solana Pay, Bitcoin Lightning, and other compatible networks or providers. Supported assets, networks, wallets, providers, confirmation rules, fees, limits, and availability may change. Digital-asset transactions may involve public blockchain networks, wallet software, provider-controlled accounts, smart contracts, network fees, transaction hashes, QR codes, deep links, confirmations, and irreversible transfers. Public blockchain data may be visible to third parties and may not be deleted, altered, reversed, or concealed by PineTree. PineTree does not guarantee the stability, redemption, liquidity, legality, tax treatment, or future availability of a digital asset. Merchants and customers bear risks including volatility, network congestion, failed or delayed transactions, incorrect addresses or networks, unsupported assets, smart-contract failures, wallet compromise, chain reorganizations, protocol changes, and regulatory developments. Bitcoin Lightning functionality may be delivered through PineTree-connected infrastructure. PineTree may present a unified merchant experience while an underlying provider supplies account, invoice, custody, balance, or network capabilities. Public-facing PineTree interfaces may identify the payment rail as Bitcoin Lightning without identifying every underlying technical vendor. 8. Custody, Wallets, and Funds Flow ----------------------------------- Unless expressly stated in a separate written agreement, PineTree does not custody merchant funds, customer funds, private keys, seed phrases, wallet recovery phrases, or cardholder funds. Funds may settle to a merchant-controlled wallet, a merchant's provider account, a provider-controlled custodial account, a connected financial account, or another destination configured under the applicable provider relationship. PineTree may display balances, transaction history, addresses, or payout status obtained from providers, public blockchains, or approved APIs. Balance visibility does not mean PineTree owns, controls, guarantees, or insures the underlying funds or digital assets. PineTree will never request a wallet seed phrase, private key, recovery phrase, card PIN, or complete card verification value through ordinary support channels. Users must not disclose these credentials to PineTree or anyone claiming to represent PineTree. 9. Merchant Onboarding and Ongoing Responsibilities --------------------------------------------------- Merchants must provide accurate, current, and complete business, ownership, identity, contact, tax, website, product, and transaction information. Merchants must maintain accurate provider accounts, authorized-user access, terminal locations, wallet addresses, callback URLs, webhook endpoints, and other configuration used with PineTree. Merchants are responsible for: - Maintaining all licenses, registrations, permits, disclosures, and policies required for their business. - Selling only lawful goods and services and accurately describing their products, pricing, delivery terms, and refund policies. - Complying with provider terms, card-network rules, acceptable-use restrictions, and applicable laws. - Responding to provider information requests, underwriting reviews, KYC or KYB requests, disputes, fraud inquiries, audits, and compliance reviews. - Managing employees, contractors, agents, API users, and other Authorized Users. - Securing accounts, devices, terminals, websites, API keys, wallet credentials, and provider credentials. - Reconciling payments, settlements, fees, refunds, chargebacks, taxes, and accounting records. - Providing required notices and obtaining required consents from customers and users. PineTree may restrict or terminate access when a merchant fails to provide requested information, cannot maintain an approved provider relationship, presents unacceptable risk, violates law or policy, or threatens the security or integrity of the platform. 10. Anti-Money-Laundering, Sanctions, Fraud, and Risk Controls -------------------------------------------------------------- Depending on the service and legal requirements, PineTree or a connected provider may perform identity checks, business verification, beneficial-owner review, sanctions screening, wallet screening, fraud review, device analysis, transaction monitoring, velocity checks, risk scoring, manual review, or other controls. PineTree may share relevant information with providers and service vendors as described in the Privacy Policy and applicable agreements. PineTree does not represent that its controls replace a merchant's own compliance program. Merchants must not rely exclusively on PineTree or a provider to identify illegal, sanctioned, fraudulent, deceptive, or otherwise prohibited activity connected to the merchant's business. PineTree may delay, reject, restrict, suspend, or report activity when reasonably necessary to comply with law, legal process, provider requirements, sanctions obligations, fraud controls, security requirements, or platform policies. PineTree may cooperate with law enforcement, regulators, providers, card networks, financial institutions, and other authorized parties when legally required or reasonably necessary to protect the platform and its users. 11. Prohibited and Restricted Activity -------------------------------------- PineTree may prohibit or restrict any activity that is illegal, deceptive, abusive, unsafe, inconsistent with provider rules, or likely to expose PineTree, merchants, customers, providers, or the public to unacceptable risk. Prohibited or restricted activity may include: - Fraud, scams, deceptive billing, unauthorized charges, fake investment opportunities, or misrepresentation. - Money laundering, terrorist financing, sanctions evasion, human trafficking, exploitation, or organized criminal activity. - Illegal gambling, unlawful financial services, unlicensed money transmission, unlicensed securities activity, or prohibited investment schemes. - Illegal drugs, unauthorized pharmaceuticals, unlawful weapons, stolen goods, counterfeit goods, or prohibited digital content. - Malware, ransomware, credential theft, unauthorized surveillance, privacy invasion, or cybercrime. - Transactions involving sanctioned or prohibited persons, entities, wallets, jurisdictions, or activities. - Any product, service, or activity prohibited by a connected provider, card network, financial institution, blockchain service, or applicable law. This list is illustrative and not exhaustive. PineTree may apply additional restrictions based on provider requirements, risk assessments, jurisdictions, or product-specific rules. 12. Consumer Protection, Refunds, Disputes, and Chargebacks ----------------------------------------------------------- Merchants are responsible for obtaining valid authorization, accurately describing charges, delivering goods or services, providing receipts and required disclosures, honoring stated refund and cancellation policies, responding to customer inquiries, and complying with consumer-protection laws. Card refunds, disputes, retrieval requests, chargebacks, reserves, representment, and related decisions are generally handled under the connected provider's and card network's rules. PineTree may display dispute information or facilitate technical workflows but does not control final dispute outcomes or card-network decisions. Digital-asset refunds are not automatically created by reversing the original blockchain transaction. A merchant may need to initiate a separate transaction through a supported wallet or provider. Merchants are responsible for confirming the correct recipient address, network, asset, amount, fees, and authorization before issuing a digital-asset refund. 13. Fees and Pricing Disclosures -------------------------------- Where applicable, PineTree currently charges a $0.15 Platform Fee per transaction. The Platform Fee may be charged to the merchant, included in the customer-facing total, or applied through another disclosed method depending on the merchant configuration, applicable law, and product terms. Connected providers, card networks, banks, wallets, blockchain networks, terminal vendors, commerce platforms, and other third parties may charge separate processing, interchange, network, gas, conversion, terminal, dispute, settlement, payout, subscription, or service fees. PineTree does not control third-party fees unless expressly stated. The applicable PineTree pricing page, merchant agreement, order form, dashboard configuration, or other written pricing terms control if they differ from this general disclosure. 14. Transaction States, Records, and Reconciliation --------------------------------------------------- PineTree standardizes payment lifecycle information across supported rails using statuses such as CREATED, PENDING, PROCESSING, CONFIRMED, FAILED, INCOMPLETE, EXPIRED, or similar states. These statuses are based on PineTree records, provider responses, webhooks, terminal events, wallet activity, and blockchain confirmations. A PineTree status is an operational representation and may not be the final legal, accounting, network, or settlement determination. Provider settlement reports, acquiring records, bank records, wallet records, blockchain data, and card-network decisions may remain authoritative for their respective functions. Merchants must independently reconcile PineTree reports against provider statements, bank deposits, wallet balances, tax records, inventory records, chargebacks, and refunds. Merchants must promptly report discrepancies and preserve relevant records. 15. Security and Access Controls -------------------------------- PineTree uses administrative, technical, and organizational controls intended to protect platform systems and information. Depending on the environment and service, controls may include authentication, role-based access, service separation, encryption in transit, secret management, audit logging, event monitoring, restricted administrative access, environment isolation, backups, and incident-response procedures. No technology platform can guarantee absolute security. Merchants and Authorized Users must use strong unique passwords, protect email accounts, enable available security features, limit access to personnel with a legitimate business need, rotate compromised credentials, secure API keys and webhooks, update devices, and promptly notify PineTree of suspected compromise. PineTree may revoke sessions, API keys, provider connections, or account access when reasonably necessary to address a security risk. 16. Data Protection and Privacy ------------------------------- PineTree handles personal information, merchant information, transaction data, device data, provider metadata, and support information as described in the PineTree Privacy Policy. Connected providers and third-party services process information under their own privacy policies, legal obligations, and agreements. Merchants are responsible for providing appropriate privacy notices, obtaining legally required consents, limiting data submitted through PineTree, responding to customer rights requests when the merchant controls the information, and avoiding the submission of sensitive data that PineTree has not requested. 17. Operational Resilience and Third-Party Dependency ----------------------------------------------------- PineTree depends on third-party providers, cloud services, databases, internet connectivity, card networks, terminal manufacturers, wallet software, public blockchains, node or RPC providers, email services, and other infrastructure. PineTree does not guarantee uninterrupted, error-free, or always-available service. Transactions or platform features may be delayed, unavailable, duplicated, rejected, reversed, or inaccurately displayed because of maintenance, provider outages, webhook delays, blockchain congestion, chain reorganizations, wallet failures, terminal issues, internet outages, software defects, fraud controls, regulatory restrictions, or force majeure events. PineTree may perform maintenance, disable features, alter routing, restrict a provider, or suspend a payment rail to protect users, comply with requirements, or preserve platform stability. PineTree will not reroute a payment to a different provider or rail unless the merchant has enabled and authorized the relevant configuration. 18. Commerce Connectors, APIs, and Webhooks ------------------------------------------- PineTree may connect with commerce platforms such as Shopify and WooCommerce or provide APIs, software development resources, webhooks, checkout links, and integration tools. These connections may synchronize order references, product or inventory identifiers, payment status, customer-provided information, and related metadata when authorized by the merchant. Merchants and developers are responsible for securing credentials, validating webhook signatures, protecting callback endpoints, following documentation and rate limits, preventing unauthorized use, testing integrations, handling duplicate events, maintaining idempotency, and complying with the terms of connected commerce platforms and providers. PineTree may revoke, rotate, suspend, or limit API and connector access for security, misuse, provider restrictions, excessive load, nonpayment, or policy violations. 19. Recordkeeping, Audit, and Cooperation ----------------------------------------- PineTree may retain transaction records, provider references, payment events, configuration history, audit logs, support records, security events, consent records, and related information for operational, legal, tax, accounting, compliance, security, dispute, and audit purposes, subject to the Privacy Policy and applicable law. Merchants must retain records required for their business and cooperate with reasonable PineTree or provider requests concerning transactions, disputes, refunds, fraud, compliance, security incidents, legal process, or audits. PineTree may preserve records after account termination when reasonably necessary or legally required. 20. Geographic Availability and Jurisdictional Limits ----------------------------------------------------- PineTree services, providers, payment methods, digital assets, terminal models, settlement options, and commerce connectors may not be available in every country, state, territory, or jurisdiction. Availability may depend on provider approval, merchant location, customer location, business type, currency, asset, network, transaction amount, licensing, sanctions, and local law. Merchants may not use PineTree to avoid geographic restrictions, provider limitations, sanctions, licensing obligations, or other legal requirements. PineTree may use account, device, IP, business, provider, wallet, or transaction information to enforce availability restrictions where appropriate. 21. Beta Features, Roadmap Items, and Certifications ---------------------------------------------------- PineTree may offer beta, test, preview, pilot, limited-availability, or certification-dependent features. Such features may be incomplete, unstable, limited to specific providers or hardware, or discontinued without becoming generally available. References to planned integrations, certifications, provider discussions, product roadmaps, or future services do not constitute a promise, guarantee, or binding commitment. Public statements should not be interpreted as representing that an integration, terminal, certification, license, or provider capability is complete unless PineTree expressly identifies it as available. 22. Regulatory References ------------------------- Depending on the service and circumstances, PineTree, merchants, or connected providers may be subject to or consider requirements and guidance associated with the Bank Secrecy Act, Financial Crimes Enforcement Network rules and guidance, Office of Foreign Assets Control sanctions, federal and state consumer-protection laws, state money-transmission laws, privacy and data-security laws, card-network rules, PCI DSS, tax laws, electronic-communications laws, and other applicable requirements. The inclusion of a law, agency, or standard in this policy does not mean PineTree represents that every listed requirement applies to PineTree, that PineTree is licensed or supervised by the named agency, or that a regulator has approved PineTree's platform. Applicability must be evaluated based on the specific activity, jurisdiction, and facts. 23. Changes to This Policy -------------------------- PineTree may update this policy as the platform, provider relationships, funds flow, security controls, services, laws, regulations, or industry standards change. Material updates may be posted on the PineTree website, communicated by email, or displayed through the merchant dashboard. The effective date and last-updated date will identify the current version. 24. Contact and Compliance Inquiries ------------------------------------ Questions regarding this policy, PineTree's operational model, provider architecture, security practices, or compliance approach may be directed to: PineTree Payments LLC Email: info@pinetree-payments.com Website: https://www.pinetree-payments.com Legal, regulatory, law-enforcement, or formal compliance requests should clearly identify the requesting party, legal authority, relevant account or transaction information, requested records, and a valid method for PineTree to verify the request.