Privacy Policy Effective Date: July 17, 2026 Last Updated: July 17, 2026 Introduction PineTree Payments LLC ("PineTree," "PineTree Payments," "we," "our," or "us") provides payment orchestration software and related services for merchants, software platforms, developers, and their customers. Our Services may include the PineTree website, merchant dashboard, point-of-sale tools, hosted checkout, payment links, PineTree Wallet interfaces, reporting and reconciliation tools, provider connections, commerce connectors, APIs, webhooks, support tools, and related products and services. This Privacy Policy explains how PineTree collects, uses, discloses, retains, and protects personal information and business information when people visit our website, create or use a PineTree account, connect a payment provider or wallet, use a terminal or checkout flow, interact with a PineTree-powered payment experience, use our developer tools, contact us, or otherwise use the Services. PineTree is primarily a software and orchestration provider. Payment processors, gateways, acquiring banks, card networks, wallet providers, digital asset infrastructure providers, blockchain networks, commerce platforms, and other connected providers may collect and process information under their own terms and privacy notices. This Privacy Policy applies only to PineTree's processing of information and does not replace the privacy notices of those third parties. 1. Scope and Privacy Roles This Privacy Policy applies to merchants and prospective merchants; account owners and Authorized Users; developers and platform users; customers who interact with PineTree-powered POS, checkout, payment-link, QR, wallet, or terminal experiences; website visitors; and people who contact PineTree regarding sales, support, partnerships, employment, or other business matters. Depending on the context, PineTree may act in different privacy roles. For information PineTree uses to establish and administer accounts, secure and improve the Services, manage billing, prevent fraud, comply with law, and operate its business, PineTree generally determines the purposes and means of processing and acts as a business or controller. For certain Customer information that PineTree processes solely to provide payment, checkout, reporting, or integration services on a Merchant's instructions, PineTree may act as a service provider or processor for that Merchant. Merchants are responsible for providing their own privacy notices to Customers and Authorized Users when required, identifying an appropriate legal basis, obtaining required consents, and ensuring they have the right to send information to PineTree and connected Providers. A separate data processing agreement may apply where required by law or contract. 2. Definitions "Authorized User" means an employee, contractor, agent, developer, or representative authorized by a Merchant to access or use the Services. "Customer" means a person or entity that pays, attempts to pay, or otherwise interacts with a Merchant through a PineTree-powered payment experience. "Merchant" means a business, organization, platform, marketplace, nonprofit, or other entity that uses or seeks to use the Services. "Personal Information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an individual or household. The definition may vary under applicable law. "Provider" means a third party that provides payment processing, acquiring, gateway, terminal, wallet, custody, blockchain, settlement, identity, compliance, hosting, commerce, communications, analytics, or other infrastructure used with the Services. "Provider Account" means an account, connected account, sub-account, gateway profile, terminal location, wallet account, or similar account maintained with a Provider for a Merchant or for the Merchant's use. "Services" has the meaning described in the introduction to this Privacy Policy. 3. Information We Collect The information PineTree collects depends on the Services used, the Merchant's configuration, the Payment Rail or Provider involved, and how a person interacts with PineTree. We may collect the categories described below. 3.1 Account and Business Information We may collect legal and trade names, business email addresses, account-owner and Authorized User names, phone numbers, business addresses, websites, business type, industry, products and services, operating locations, tax-related settings, company identifiers, merchant preferences, account roles, permissions, billing information, support plan information, and other information needed to create, administer, or support a PineTree account. We may collect information submitted through website forms, waitlists, product-interest forms, sales inquiries, onboarding forms, support requests, and partnership communications. 3.2 Identity, Verification, and Provider Onboarding Information Connected Providers may require identity verification, beneficial-owner information, KYC or KYB review, sanctions screening, underwriting, bank-account verification, tax information, or other compliance information. Providers generally collect sensitive verification documents and financial account details directly through Provider-controlled interfaces. PineTree may receive or store limited onboarding information such as Provider Account identifiers, application status, verification status, capabilities, requested requirements, approval or restriction status, business profile information, and risk or compliance messages needed to display status or support the integration. PineTree does not control a Provider's verification or underwriting decisions. 3.3 Authentication and Security Information We may collect email addresses, authentication identifiers, password hashes maintained by our authentication infrastructure, session identifiers, account roles, permissions, login dates and times, IP addresses, browser and device information, failed login attempts, recovery activity, multifactor-authentication events, API-key metadata, security alerts, and audit records. We use this information to authenticate users, maintain sessions, restrict access, investigate suspicious activity, protect accounts, and document administrative actions. 3.4 Provider Connection and Configuration Information When a Merchant connects or enables a Provider, we may collect Provider names, Provider Account IDs, connected-account IDs, merchant profiles, authorization scopes, encrypted access or refresh tokens, webhook configuration, capabilities, payment-method availability, settlement and payout status, terminal locations, reader identifiers, gateway settings, and integration health information. PineTree may retrieve balances, transaction summaries, account status, and configuration data from Providers when authorized by the Merchant and permitted by Provider terms. 3.5 Payment, Order, and Transaction Information We may collect payment IDs, Merchant and Customer references, order numbers, item or cart references, subtotals, discounts, taxes, tips, PineTree fees, gross amounts, currency, asset, Payment Rail, Provider, network, payment method, status, authorization result, decline or failure reason, Provider reference, timestamps, idempotency keys, event history, refund and cancellation information, chargeback or dispute status, settlement-related metadata, receipt information, and reconciliation records. PineTree standardizes Provider and network events into transaction states and event records so that Merchants can view payment progress, reporting, and history across connected Providers. Raw Provider webhook payloads or portions of those payloads may be retained for verification, debugging, fraud review, audit, and reconciliation. 3.6 Card and Terminal Information PineTree is designed so that full card numbers, card security codes, PINs, and other sensitive authentication data are entered into Provider-controlled interfaces, hosted fields, iFrames, SDKs, payment elements, or terminals rather than PineTree free-text fields or ordinary PineTree application databases. PineTree may receive tokenized or limited card information from Providers, including a payment-method token or ID, card brand, last four digits, expiration month and year, funding type, card-present or card-not-present indicator, authorization status, decline code, risk result, terminal or reader ID, terminal location, device status, and transaction reference. Connected Providers may separately collect and process cardholder and payment-card information under their privacy notices. For terminal operations, we may collect Merchant-created location names and addresses, reader labels, reader serial or registration identifiers, connectivity and software status, last activity, default-reader settings, and test or simulated-reader information. We do not intentionally collect precise device geolocation unless a feature specifically requests it and provides notice. 3.7 Digital Asset, Wallet, and Blockchain Information When a Merchant or Customer uses a supported digital-asset payment flow, PineTree may collect or process public wallet addresses, wallet type, network or chain, asset, token contract, amount, payment URI, QR payload, transaction signature or hash, block or slot information, network confirmations, transaction status, balance information, allowance or approval status, and related event data. PineTree Wallet may display information from Merchant-controlled wallets, Provider-controlled accounts, public blockchain data, or authorized Provider APIs. A displayed balance does not necessarily mean PineTree has custody or control of the underlying asset. PineTree does not ask for or intend to collect private keys, seed phrases, recovery phrases, wallet passwords, or other secret wallet credentials. Users should never provide those credentials to PineTree or through PineTree support channels. 3.8 Bitcoin Lightning Information For Bitcoin Lightning payments, PineTree may collect Lightning invoices or invoice identifiers, payment hashes, amounts, expiration times, payment status, settlement or confirmation events, balance information, withdrawal or payout references, Merchant account or sub-account identifiers, and technical metadata received from PineTree's underlying Bitcoin Lightning infrastructure provider. The underlying infrastructure provider may maintain a Provider Account or custodial account for a Merchant and may collect additional identity, compliance, wallet, payout, or transaction information under its own privacy notice. PineTree may receive account status, transaction, balance, and event information needed to provide the unified PineTree experience. 3.9 Hosted Checkout, Payment Links, and Customer Information When a Customer uses hosted checkout, a payment link, a POS flow, or another PineTree-powered payment experience, we may collect the payment amount, checkout or session ID, Merchant and order reference, payment method selected, currency or asset, payment status, email address or name if requested by the Merchant or needed for the transaction, receipt information, device and browser metadata, IP address, event timestamps, and Provider or network references. The Merchant determines what Customer information it requests through its commerce or checkout flow. Merchants must not use PineTree fields to collect unnecessary sensitive information. 3.10 Commerce Connector and Inventory Information When a Merchant connects a commerce platform or inventory system, such as Shopify or WooCommerce, PineTree may collect store identifiers, store URL, encrypted authorization tokens, product and variant identifiers, SKUs, inventory quantities, prices, tax and order settings, order references, fulfillment or refund status, and synchronization metadata. PineTree uses this information to support configured checkout, order, inventory, payment-status, reporting, or reconciliation workflows. The connected commerce platform separately processes information under its own privacy notice. 3.11 APIs, Webhooks, and Developer Information We may collect developer account information, API-key identifiers, key creation and revocation dates, access scopes, IP addresses, request and response metadata, endpoint names, status codes, latency, idempotency keys, webhook endpoints, event delivery attempts, signature-verification results, retry history, error logs, user-agent information, and sandbox or production environment indicators. We use this information to authenticate requests, operate and secure developer tools, troubleshoot integrations, enforce rate limits, deliver events, prevent abuse, and maintain audit trails. 3.12 Website, Device, Cookie, and Usage Information When someone visits or uses the website, dashboard, checkout, POS, or other web interfaces, we may automatically collect IP address, browser type, operating system, device type, screen or viewport information, language, referring URL, pages viewed, date and time, session identifiers, cookie or local-storage identifiers, navigation and interaction events, performance data, crash or error information, and approximate location inferred from IP address. We may use cookies, local storage, session storage, and similar technologies for authentication, security, preferences, performance, analytics, and fraud prevention. Additional information is provided in the Cookies and Similar Technologies section below. 3.13 Communications, Support, Sales, and Feedback We may collect names, email addresses, phone numbers, business names, message content, attachments, screenshots, transaction or account references, support category, priority, communication history, meeting notes, survey responses, feedback, and resolution information when a person contacts us or participates in a sales, support, partnership, or research interaction. 3.14 Information We Do Not Intend to Collect Do not submit private keys, seed phrases, recovery phrases, wallet passwords, full card numbers, card security codes, PINs, account passwords, or other secret credentials through support messages, free-text fields, screenshots, logs, or APIs unless PineTree documentation expressly permits the specific data for a supported secure workflow. PineTree does not intentionally collect medical records, biometric templates, precise personal geolocation, consumer credit reports, or information about children through the ordinary operation of the Services. A Provider may collect additional information directly when required for its services. 4. Sources of Information PineTree may collect information directly from Merchants, Authorized Users, Customers, developers, website visitors, and people who contact us. We may also receive information from connected Providers, payment processors, gateways, acquiring institutions, card networks, terminals, wallet infrastructure providers, public blockchain networks, blockchain nodes or explorers, commerce platforms, identity and compliance providers, cloud and authentication providers, fraud and security tools, email and support providers, and other service providers. We may generate information through PineTree Engine, including normalized transaction states, event records, routing decisions, fee calculations, reporting summaries, alerts, risk signals, and operational analytics. We may also derive approximate location from an IP address and create inferences about account or product usage for security, support, and product improvement. 5. How We Use Information PineTree may use information to: - create, verify, administer, and support Merchant accounts and Authorized Users; - authenticate users and maintain secure sessions; - connect, configure, monitor, and support Provider Accounts and Payment Rails; - create and route payment instructions through PineTree Engine; - operate POS, hosted checkout, payment links, card, terminal, wallet, stablecoin, blockchain, and Bitcoin Lightning experiences; - display balances, payment status, transaction history, events, reports, exports, and reconciliation information; - support refunds, cancellations, disputes, chargebacks, withdrawals, and other Provider-supported actions; - synchronize configured products, inventory, orders, and payment status with commerce platforms; - operate APIs, webhooks, SDKs, sandboxes, and other developer tools; - calculate and administer PineTree fees and billing; - provide service communications, support, onboarding, and product notices; - detect, investigate, prevent, and respond to fraud, abuse, security incidents, sanctions concerns, prohibited activity, and technical failures; - verify compliance with the Terms of Service, Provider requirements, and applicable law; - monitor availability, performance, usage, and integration health; - debug, maintain, test, improve, and develop the Services; - create aggregated, statistical, or de-identified information for analytics, reliability, product planning, and business operations; - establish, exercise, or defend legal claims and respond to lawful requests; - complete a corporate transaction, audit, financing, insurance review, or professional-adviser engagement; and - perform other purposes disclosed at the time information is collected or with appropriate authorization. PineTree does not use full payment-card credentials or secret wallet credentials for advertising or unrelated analytics. 6. Merchant Instructions and Customer Data A Merchant may use PineTree to collect or transmit information about its Customers, orders, employees, products, or business systems. As between PineTree and the Merchant, the Merchant determines the lawfulness of that collection and the instructions it gives PineTree, except where PineTree independently processes information for security, compliance, billing, legal, or internal operational purposes. Merchants must provide all legally required notices and obtain all required permissions before submitting Personal Information to PineTree or enabling a Provider or commerce connection. Merchants must respond to Customer requests relating to Merchant-controlled data, although PineTree may assist when required by law or contract. PineTree may refuse an instruction that violates law, the Terms of Service, Provider requirements, or reasonable security practices. 7. Legal Bases for Processing Where laws such as the European Economic Area or United Kingdom data-protection laws require a legal basis, PineTree generally relies on one or more of the following: - performance of a contract, including providing Services requested by a Merchant or user; - legitimate interests, including securing and improving the Services, preventing fraud, supporting users, managing Provider connections, maintaining records, and operating PineTree's business, balanced against applicable privacy rights; - compliance with legal obligations, lawful requests, accounting, tax, sanctions, security, and regulatory requirements; - consent, where PineTree asks for consent for a specific use and consent is legally required; and - establishment, exercise, or defense of legal claims. Where PineTree processes Customer data as a processor on a Merchant's behalf, the Merchant is responsible for identifying the applicable legal basis. 8. Payment Providers and Connected Provider Accounts Payment and settlement services are provided by independent Providers, which may include card processors and gateways such as Stripe, Shift4, and Fluid Pay; wallet and blockchain infrastructure; Base and Solana network infrastructure; Bitcoin Lightning infrastructure; banks, acquiring institutions, card networks, and other payment partners. PineTree may disclose account, transaction, technical, and onboarding information to an enabled Provider and receive information from that Provider as needed to create or manage a Provider Account, transmit instructions, display status, support transactions, reconcile records, troubleshoot issues, or satisfy legal and Provider requirements. Providers determine their own privacy practices, verification requirements, underwriting, risk review, processing, custody, settlement, reserves, and retention. Information collected directly by a Provider is governed by the Provider's privacy notice. PineTree is not responsible for a Provider's independent privacy practices. 9. Card Data, Terminals, and Payment Security PineTree seeks to minimize its receipt of sensitive card data. In normal supported integrations, card numbers, security codes, PINs, and sensitive authentication data are collected through Provider-controlled components or approved terminals. PineTree may receive tokenized card references and limited transaction information needed for status, receipts, support, reporting, and reconciliation. Merchants must not alter supported integrations to intercept or store card data through PineTree systems. A Merchant's PCI DSS and card-network responsibilities are determined by its actual environment and Provider arrangements and are not eliminated merely because processing is outsourced. Terminal and reader information may be associated with a Merchant location, device, or Authorized User. PineTree uses this information to register and manage readers, route terminal instructions, show availability, support test-mode functions, and investigate device or connectivity issues. 10. PineTree Wallet, Digital Assets, and Public Blockchains PineTree Wallet is a unified software interface that may display or coordinate information from public blockchains, Merchant-controlled wallets, Provider-controlled accounts, or other approved infrastructure. PineTree Wallet does not necessarily mean that PineTree holds, owns, or controls the underlying funds or assets. Public blockchain records may be visible to anyone, permanent, and outside PineTree's control. Wallet addresses, transaction hashes, amounts, timestamps, smart-contract interactions, and other metadata may remain publicly accessible even after a PineTree account is closed or a deletion request is completed. PineTree cannot delete, change, reverse, or conceal information recorded on a public blockchain. Requests concerning information maintained by a wallet or custody Provider may need to be directed to that Provider. 11. Bitcoin Lightning Infrastructure PineTree may use an underlying Bitcoin Lightning infrastructure provider to create or support Merchant-specific accounts, invoices, balances, payment confirmations, and authorized withdrawal or payout workflows. PineTree may send Merchant onboarding and transaction information to that provider and receive account, balance, status, event, and transaction information in return. The underlying provider may act as custodian or maintain a Provider Account for the Merchant. Its processing, verification, retention, and disclosures are governed by its own privacy notice and Provider Terms. PineTree may present the experience under PineTree branding without changing the provider's independent privacy obligations. 12. Commerce Connectors When a Merchant enables a Shopify, WooCommerce, or other commerce connector, PineTree may exchange store, product, inventory, order, Customer, refund, and payment-status information with the connected platform according to the Merchant's configuration and authorization. PineTree uses connector information only for supported operations, security, support, analytics, reconciliation, and improvement. Merchants are responsible for configuring access scopes appropriately and for their privacy obligations to store visitors and Customers. 13. How We Disclose Information PineTree may disclose information to the following categories of recipients: - Payment Providers, banks, card networks, terminal providers, wallet providers, custody providers, blockchain infrastructure providers, and other Payment Rails enabled by a Merchant; - commerce platforms and connectors, such as Shopify and WooCommerce, when authorized by a Merchant; - cloud hosting, database, authentication, storage, networking, monitoring, analytics, email, communications, and support providers, which may include Supabase, Vercel, Google Workspace, and similar service providers; - fraud-prevention, security, identity, compliance, sanctions-screening, and risk-management providers; - professional advisers, auditors, insurers, financing sources, accountants, and legal counsel subject to appropriate obligations; - government agencies, courts, regulators, law enforcement, or other parties when disclosure is required or permitted by law or reasonably necessary to protect rights, safety, security, or the integrity of the Services; - a purchaser, successor, lender, investor, or other participant in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, subject to appropriate safeguards; and - other parties at the direction of a Merchant or individual, with consent, or as disclosed at the time of collection. PineTree may also disclose aggregated or de-identified information that is not reasonably capable of identifying an individual, subject to applicable law. 14. No Sale of Personal Information or Cross-Context Behavioral Advertising As of the Effective Date, PineTree does not sell Personal Information for monetary consideration. PineTree also does not share Personal Information for cross-context behavioral advertising or use Personal Information for targeted advertising based on activity across unrelated businesses, as those terms are defined under applicable U.S. state privacy laws. PineTree may disclose information to service providers and Providers for the business and operational purposes described in this Privacy Policy. Those disclosures are not intended as sales or sharing for cross-context behavioral advertising. If PineTree changes these practices, we will update this Privacy Policy and provide any legally required opt-out mechanism before the change applies. 15. Cookies and Similar Technologies PineTree and its service providers may use cookies, local storage, session storage, pixels, SDKs, and similar technologies to keep users signed in, maintain security, remember preferences, operate forms and checkout, measure performance, detect errors, prevent abuse, and understand how the Services are used. Cookies may be session cookies that expire when a browser closes or persistent cookies that remain for a defined period. Browser settings may allow a person to block or delete cookies, but doing so may prevent authentication, checkout, dashboard, or other features from working correctly. Where required by law, PineTree will request consent before using non-essential cookies. PineTree does not currently use cookie data for cross-context behavioral advertising. 16. Aggregated, De-Identified, and Analytical Information PineTree may create aggregated, statistical, or de-identified information from account, transaction, Provider, usage, and operational data. We may use this information to measure payment volume, reliability, feature adoption, performance, fraud trends, Provider health, and other business or technical metrics. PineTree will not attempt to re-identify de-identified information except as permitted by law to test or validate the de-identification process. We may disclose aggregated or de-identified information to Providers, advisers, prospective partners, or other parties when it does not reasonably identify an individual or Merchant, subject to contractual and legal restrictions. 17. Automated Processing, Routing, and Provider Decisions PineTree Engine may use automated rules to select an enabled Provider or Payment Rail, normalize events, calculate fees, update transaction states, identify duplicate requests, detect errors, or trigger security and fraud controls. These functions support payment orchestration and platform operations. Providers may use automated systems for authorization, fraud review, identity verification, underwriting, sanctions screening, account limits, reserves, or transaction decisions. PineTree does not control a Provider's independent decision systems. Where applicable law provides a right concerning a decision based solely on automated processing that produces legal or similarly significant effects, a person may contact PineTree using the information below. PineTree may direct Provider-related requests to the responsible Provider. 18. Data Retention PineTree retains information for no longer than reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law, Provider requirements, contract, security needs, dispute resolution, audit, tax, accounting, or legitimate business needs. Retention depends on the category and context. Account and Provider-connection information may be retained for the duration of the relationship and a reasonable period afterward. Payment, ledger, refund, dispute, reconciliation, webhook, and audit records may be retained for longer periods because they support financial records, security, provider inquiries, legal claims, and compliance. Security, API, and technical logs are retained based on operational and risk needs. Marketing and inquiry information may be retained until a person unsubscribes, requests deletion where applicable, or the information is no longer useful. When information is no longer needed, PineTree may delete, anonymize, aggregate, or isolate it from active use. Backup copies may remain for a limited period until overwritten. PineTree cannot delete public blockchain records or information independently retained by Providers. 19. Data Security PineTree uses reasonable administrative, technical, and organizational safeguards designed to protect information against unauthorized access, destruction, loss, alteration, misuse, or disclosure. Safeguards may include encryption in transit, access controls, role-based permissions, authentication controls, credential separation, secure cloud infrastructure, logging, monitoring, database security policies, environment-secret protections, vulnerability management, and incident-response procedures. No security program can guarantee complete protection. Internet transmissions, cloud services, endpoints, Provider systems, terminals, wallets, and blockchain networks may be compromised or fail. Users and Merchants are responsible for protecting their devices, credentials, API keys, wallet access, terminals, networks, and Authorized User permissions. PineTree will never ask a user to disclose a wallet seed phrase or private key. A person who suspects unauthorized access should contact PineTree promptly and should also secure affected Provider, email, wallet, and financial accounts. 20. Security Incidents PineTree may investigate suspected security incidents, preserve relevant records, restrict access, rotate credentials, contact affected Providers, and take other measures reasonably necessary to protect the Services and users. If PineTree determines that a legally reportable breach has occurred, PineTree will provide notices to affected individuals, Merchants, Providers, or authorities as required by applicable law. A Merchant may have separate notification obligations for Customer data under its control. 21. International Data Transfers PineTree is based in the United States. Information may be processed or stored in the United States and in other jurisdictions where PineTree or its Providers and service providers operate. Those jurisdictions may have data-protection laws that differ from the laws where a person lives. Where required, PineTree may use contractual safeguards, adequacy mechanisms, or other lawful transfer tools for international transfers. Connected Providers may use their own transfer mechanisms under their privacy notices. 22. U.S. State Privacy Rights Depending on a person's state of residence, applicable law, and whether PineTree meets the law's coverage thresholds, the person may have rights to request that PineTree: - confirm whether PineTree processes Personal Information and provide access to it; - correct inaccurate Personal Information; - delete certain Personal Information; - provide a portable copy of certain Personal Information; - disclose categories or specific pieces of Personal Information collected, sources, purposes, and categories of recipients; - opt out of the sale of Personal Information, sharing for cross-context behavioral advertising, targeted advertising, or certain profiling; - limit certain uses or disclosures of sensitive Personal Information; and - appeal a denial of a privacy request. PineTree does not discriminate against a person for exercising an applicable privacy right. Rights are subject to exceptions, including when information is needed to complete a transaction, provide requested Services, detect fraud, maintain security, comply with law, keep financial or audit records, establish legal claims, or protect the rights of others. To submit a request, email info@pinetree-payments.com with the subject line "Privacy Request." Describe the request, the state or country of residence, the PineTree account or transaction involved, and an email address PineTree can use to verify the request. Do not send private keys, seed phrases, full card numbers, or other secret credentials. PineTree may need to verify identity and authority before completing a request. An authorized agent may submit a request where permitted, but PineTree may require proof of authorization and may verify the request directly with the individual. If PineTree denies a request, the response will explain the basis and any available appeal process. 23. California Privacy Disclosures This section supplements the Privacy Policy for California residents when the California Consumer Privacy Act, as amended, applies to PineTree. During the preceding twelve months, PineTree may have collected the following statutory categories of Personal Information: identifiers; customer-record information; commercial and transaction information; internet or other electronic-network activity; approximate geolocation information; professional or employment-related information; financial and payment-related information; account credentials and other sensitive Personal Information used for security; and inferences concerning account, product, security, or integration usage. PineTree collects these categories from the sources described in Section 4 and uses them for the purposes described in Section 5. PineTree may disclose them to the categories of recipients described in Section 13 for business purposes. PineTree does not use or disclose sensitive Personal Information for the purpose of inferring characteristics about a person. PineTree does not sell Personal Information or share it for cross-context behavioral advertising as of the Effective Date. PineTree does not knowingly sell or share the Personal Information of people under sixteen years of age. California residents may request access, correction, deletion, information about collection and disclosure, and portability, subject to legal exceptions. Because PineTree does not currently sell or share Personal Information for cross-context behavioral advertising, PineTree does not currently provide a "Do Not Sell or Share My Personal Information" link. If those practices change, PineTree will provide the legally required notice and opt-out method. 24. EEA, United Kingdom, and Other International Rights Where applicable, individuals may have rights to access, correct, erase, restrict, or object to processing; receive data portability; withdraw consent; and complain to a data-protection authority. Withdrawal of consent does not affect processing completed before withdrawal. Some rights may not apply when PineTree acts only as a processor for a Merchant. In that case, PineTree may refer the request to the Merchant. Rights may also be limited by legal, security, fraud-prevention, financial-record, and contractual obligations. Individuals in the EEA or United Kingdom may contact the data-protection authority in the country where they live or work. PineTree encourages individuals to contact us first so we can attempt to address the concern. 25. Marketing and Service Communications PineTree may send account, security, transaction, billing, Provider, policy, outage, maintenance, and other service-related communications. These messages are necessary to operate the Services and may not offer an unsubscribe option. PineTree may also send product updates, event invitations, newsletters, or other marketing communications where permitted. A recipient may unsubscribe using the link in the message or by contacting PineTree. Unsubscribing from marketing does not stop service communications. 26. Children's Privacy The Services are designed for businesses, adults, and people authorized to use business payment tools. They are not directed to children under eighteen years of age. PineTree does not knowingly collect Personal Information online from a child under thirteen. If PineTree learns that it has collected such information without legally sufficient authorization, PineTree will take reasonable steps to delete it, subject to legal and security requirements. A parent or guardian may contact PineTree using the information below. 27. Third-Party Websites and Services The Services may contain links to or integrate with websites, wallets, Providers, commerce platforms, blockchain explorers, and other third-party services. PineTree does not control those third parties and is not responsible for their privacy, security, content, availability, or data practices. Before using a third-party service, review its privacy notice, terms, permissions, and security practices. Disconnecting a Provider or connector from PineTree may not delete information retained by that third party. 28. Changes to This Privacy Policy PineTree may update this Privacy Policy to reflect changes in the Services, Providers, Payment Rails, legal requirements, or data practices. PineTree will update the "Last Updated" date and may provide additional notice through the website, dashboard, or email when changes are material. The updated Privacy Policy applies when posted or on a later date stated in the notice. Continued use of the Services after the effective date of an update constitutes acknowledgment of the updated policy, but PineTree will obtain consent where consent is legally required. 29. Contact PineTree Questions, complaints, and privacy requests may be directed to: PineTree Payments LLC Email: info@pinetree-payments.com Website: https://www.pinetree-payments.com For a privacy request, use the subject line "Privacy Request" and include enough information for PineTree to identify the relevant account or interaction. Do not include private keys, seed phrases, full card numbers, security codes, or account passwords.